aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorHenry Sudhof <kellanved@phpbb.com>2009-08-03 13:32:52 +0000
committerHenry Sudhof <kellanved@phpbb.com>2009-08-03 13:32:52 +0000
commitd376811e7faf1f947645c9bfedd235c6ae9e3227 (patch)
treea450d982effe30daa7bf9442bffb35b002960964 /phpBB/ucp.php
parent#48965 (diff)
downloadphpbb-d376811e7faf1f947645c9bfedd235c6ae9e3227.tar.gz
phpbb-d376811e7faf1f947645c9bfedd235c6ae9e3227.tar.bz2
phpbb-d376811e7faf1f947645c9bfedd235c6ae9e3227.zip
require link hash for switchperm
git-svn-id: file:///svn/phpbb/branches/phpBB-3_0_0@9915 89ea8834-ac86-4346-8a33-228a782c2dd0
Diffstat (limited to 'phpBB/ucp.php')
-rw-r--r--phpBB/ucp.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/phpBB/ucp.php b/phpBB/ucp.php
index b808049187..061933fb0c 100644
--- a/phpBB/ucp.php
+++ b/phpBB/ucp.php
@@ -186,7 +186,7 @@ switch ($mode)
$user_row = $db->sql_fetchrow($result);
$db->sql_freeresult($result);
- if (!$auth->acl_get('a_switchperm') || !$user_row || $user_id == $user->data['user_id'])
+ if (!$auth->acl_get('a_switchperm') || !$user_row || $user_id == $user->data['user_id'] || !check_link_hash(request_var('hash', ''), 'switchperm'))
{
redirect(append_sid("{$phpbb_root_path}index.$phpEx"));
}