Merge pull request #1049 from ice123123123/patch-1

security fix for reseller Accounts
This commit is contained in:
Ulrich Block 2018-01-01 14:42:24 +01:00 committed by GitHub
commit 09a48f1b03
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -70,7 +70,7 @@ if ($ui->id('id', 19, 'get')) {
$sql = null;
if ($row['accounttype'] == 'u') {
if ($row['accounttype'] == 'u' && $row['resellerid'] == $reseller_id) {
$_SESSION['userid'] = $ui->id('id', 19, 'get');
@ -103,4 +103,4 @@ if ($ui->id('id', 19, 'get')) {
}
}
$sql = null;
redirect('login.php');
redirect('login.php');