From 11f13e21ac9c3cdcbe8e059938fdbac832b9b441 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Rub=C3=A9n=20Calvo?= Date: Fri, 8 Sep 2017 17:01:13 +0200 Subject: [PATCH] [ticket/15289] Check form PHPBB3-15289 --- phpBB/includes/acp/acp_storage.php | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/phpBB/includes/acp/acp_storage.php b/phpBB/includes/acp/acp_storage.php index 74cb64e76c..9998188a18 100644 --- a/phpBB/includes/acp/acp_storage.php +++ b/phpBB/includes/acp/acp_storage.php @@ -79,8 +79,8 @@ class acp_storage public function overview($id, $mode) { - $form_name = 'acp_storage'; - add_form_key($form_name); + $form_key = 'acp_storage'; + add_form_key($form_key); // Template from adm/style $this->tpl_name = 'acp_storage'; @@ -93,6 +93,11 @@ class acp_storage $modified_storages = []; $messages = []; + if (!check_form_key($form_key)) + { + $messages[] = $this->lang->lang('FORM_INVALID'); + } + foreach ($this->storage_collection as $storage) { $storage_name = $storage->get_name();