Skip to content
Browse files

Corrected Security Check at line 46 and 96

  • Loading branch information...
1 parent 9fcce3a commit 749a9fcd396c839cb6a4d5b0454b82d12c1f46da @ThiloWitt committed
Showing with 2 additions and 2 deletions.
  1. +2 −2 src/system/Blocks/lib/Blocks/Block/Menutree.php
View
4 src/system/Blocks/lib/Blocks/Block/Menutree.php
@@ -43,7 +43,7 @@ public function info()
public function display($blockinfo)
{
// Security check
- if (!Securityutil::checkPermission('Menutree:menutreeblock:', "{$blockinfo['bid']}::", ACCESS_READ)) {
+ if (!Securityutil::checkPermission('Menutree:menutreeblock:', $blockinfo['bid'] . '::' , ACCESS_READ)) {
return false;
}
@@ -93,7 +93,7 @@ public function display($blockinfo)
foreach ($vars['menutree_content'] as $id => $item) {
$item = $item[$lang];
// check the permission access to the current link
- $hasperms = Securityutil::checkPermission('Menutree:menutreeblock:',"$blockinfo[bid]:$item[name]:$item[id]", ACCESS_READ);
+ $hasperms = Securityutil::checkPermission('Menutree:menutreeblock:', $blockinfo[bid] . ':' . $item[name] . ':' . $item[id] , ACCESS_READ);
// checks if has no access to it or the link is not active
if (!$hasperms || in_array($item['parent'], $blocked) || $item['state'] != 1) {
$blocked[] = $item['id'];

1 comment on commit 749a9fc

@ThiloWitt
Owner
Please sign in to comment.
Something went wrong with that request. Please try again.