Add default value for search_users (path disclosure) - refs #2746

pull/2757/head
Yannick Warnier 7 years ago
parent da8a93eea4
commit 15e49c1737
  1. 3
      main/admin/dashboard_add_users_to_user.php

@ -63,7 +63,7 @@ if (!api_is_platform_admin()) {
api_not_allowed(true);
}
function search_users($needle, $type)
function search_users($needle, $type = 'multiple')
{
global $tbl_access_url_rel_user, $tbl_user, $user_anonymous, $current_user_id, $user_id, $userStatus;
@ -365,6 +365,7 @@ if (count($assigned_users_id) > 0) {
}
$search_user = '';
$needle = '';
if (!empty($firstLetterUser)) {
$needle = Database::escape_string($firstLetterUser);
$search_user = "AND ".(api_sort_by_first_name() ? 'firstname' : 'lastname')." LIKE '$needle%'";

Loading…
Cancel
Save