From 81736a01299f7c963e361e9b192df074999d16d8 Mon Sep 17 00:00:00 2001 From: Klaus Weidenbach Date: Wed, 29 Mar 2017 23:53:03 +0200 Subject: :lock: Add CSRF protection for import and import_items. --- Zotlabs/Module/Import_items.php | 3 +++ 1 file changed, 3 insertions(+) (limited to 'Zotlabs/Module/Import_items.php') diff --git a/Zotlabs/Module/Import_items.php b/Zotlabs/Module/Import_items.php index 133e37d9e..c2b2506fe 100644 --- a/Zotlabs/Module/Import_items.php +++ b/Zotlabs/Module/Import_items.php @@ -15,6 +15,8 @@ class Import_items extends \Zotlabs\Web\Controller { if(! local_channel()) return; + check_form_security_token_redirectOnErr('/import_items', 'import_items'); + $data = null; $src = $_FILES['filename']['tmp_name']; @@ -123,6 +125,7 @@ class Import_items extends \Zotlabs\Web\Controller { '$title' => t('Import Items'), '$desc' => t('Use this form to import existing posts and content from an export file.'), '$label_filename' => t('File to Upload'), + '$form_security_token' => get_form_security_token('import_items'), '$submit' => t('Submit') )); -- cgit v1.2.3