diff -r d8983d3a8468 -r 2e635e51deb0 plugins/PrivateMessages.php
--- a/plugins/PrivateMessages.php Tue Jul 12 22:15:18 2011 -0400
+++ b/plugins/PrivateMessages.php Tue Jul 12 22:21:08 2011 -0400
@@ -153,6 +153,7 @@
if ( $argv[1]=='Send' && isset($_POST['_send']) )
{
// Check each POST DATA parameter...
+ csrf_request_confirm();
$errors = array();
if(!isset($_POST['to']) || ( isset($_POST['to']) && $_POST['to'] == ''))
{
@@ -195,6 +196,7 @@
}
else if ( $argv[1] == 'Send' && isset($_POST['_savedraft'] ) )
{
+ csrf_request_confirm();
$errors = array();
if ( !isset($_POST['to']) || ( isset($_POST['to']) && $_POST['to'] == '') )
{
@@ -303,6 +305,7 @@
}
?>
+
get('privmsgs_lbl_compose_th'); ?> |
@@ -416,6 +419,7 @@
}
else if ( isset($_POST['_savedraft']) )
{
+ csrf_request_confirm();
// Check each POST DATA parameter...
$errors = array();
if(!isset($_POST['to']) || ( isset($_POST['to']) && $_POST['to'] == ''))
@@ -467,6 +471,7 @@
echo '' . $lang->get('privmsgs_msg_draft_saved') . '
';
}
?>
+
+ echo '
+
+
' . $lang->get('privmsgs_btn_compose') . '
';
@@ -657,6 +664,7 @@
$template->footer();
break;
case 'PostHandler':
+ csrf_request_confirm();
$fname = $db->escape(strtolower($_POST['folder']));
if($fname=='drafts' || $fname=='outbox')
{