mirror of
https://github.com/itflow-org/itflow
synced 2026-03-11 00:04:50 +00:00
Add missing CSRF Checks in admin area and settings
This commit is contained in:
@@ -54,6 +54,8 @@ if (isset($_POST['edit_company'])) {
|
||||
|
||||
if (isset($_GET['remove_company_logo'])) {
|
||||
|
||||
validateCSRFToken($_GET['csrf_token']);
|
||||
|
||||
$sql = mysqli_query($mysqli,"SELECT company_logo FROM companies");
|
||||
$row = mysqli_fetch_assoc($sql);
|
||||
$company_logo = $row['company_logo']; // FileSystem Operation Logo is already sanitized
|
||||
|
||||
Reference in New Issue
Block a user