Dotclear


Ignore:
Timestamp:
11/06/11 16:32:00 (14 years ago)
Author:
xave
Branch:
default
Message:

Antispam plugin ecurity fix: user rights on the selected blog are now checked. Thanks to Romuald Brunet.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • plugins/antispam/inc/lib.dc.antispam.php

    r472 r752  
    163163          } 
    164164           
     165          $permissions = $core->getBlogPermissions($core->blog->id); 
     166           
     167          if ( empty($permissions[$rs->user_id]) ) { 
     168               return false; 
     169          } 
     170           
    165171          return $rs->user_id; 
    166172     } 
Note: See TracChangeset for help on using the changeset viewer.

Sites map