diff --git a/main/exercice/exercise_history.php b/main/exercice/exercise_history.php index 9d2fb316cd..23bda2a92b 100755 --- a/main/exercice/exercise_history.php +++ b/main/exercice/exercise_history.php @@ -25,9 +25,9 @@ if (!$is_allowedToEdit){ exit; } -$interbreadcrumb[]= array ('url' => 'exercise_report.php','name' => get_lang('Exercises')); -$interbreadcrumb[]= array ('url' => 'exercise_report.php'.'?filter=2','name' => get_lang('StudentScore')); -$interbreadcrumb[]= array ('url' => 'exercise_history.php'.'?exe_id='.intval($_GET['exe_id']), 'name' => get_lang('Details')); +$interbreadcrumb[]= array ('url' => 'exercise_report.php?'.api_get_cidreq(),'name' => get_lang('Exercises')); +$interbreadcrumb[]= array ('url' => 'exercise_report.php?filter=2&'.api_get_cidreq(),'name' => get_lang('StudentScore')); +$interbreadcrumb[]= array ('url' => 'exercise_history.php?exe_id='.intval($_GET['exe_id']).'&'.api_get_cidreq(), 'name' => get_lang('Details')); $TBL_USER = Database::get_main_table(TABLE_MAIN_USER); $TBL_EXERCISES = Database::get_course_table(TABLE_QUIZ_TEST); @@ -43,7 +43,8 @@ if (isset($_GET['message'])) { } echo '
'; ?> diff --git a/main/exercice/exercise_report.php b/main/exercice/exercise_report.php index e47108e7e3..0094e14bce 100755 --- a/main/exercice/exercise_report.php +++ b/main/exercice/exercise_report.php @@ -289,7 +289,7 @@ if (($is_allowedToEdit || $is_tutor || api_is_coach()) && Database::query($sql); $sql = 'DELETE FROM '.$TBL_TRACK_ATTEMPT.' WHERE exe_id = '.$exe_id; Database::query($sql); - header('Location: exercise_report.php?cidReq='.Security::remove_XSS($_GET['cidReq']).'&exerciseId='.$exercise_id); + header('Location: exercise_report.php?'.api_get_cidreq().'&exerciseId='.$exercise_id); exit; } } @@ -623,7 +623,7 @@ $extra_params['height'] = 'auto'; }); }); -