浏览代码

A quick-fix for the reported exploit with themes.

graf25 23 年之前
父节点
当前提交
69a20d53fd
共有 1 个文件被更改,包括 9 次插入0 次删除
  1. 9 0
      src/validate.php

+ 9 - 0
src/validate.php

@@ -61,6 +61,15 @@ if (isset($send)
 * Include them down here instead of at the top so that all config
 * variables overwrite any passed in variables (for security).
 */
+
+/**
+ * Reset the $theme() array in case a value was passed via a cookie.
+ * This is until theming is rewritten.
+ */
+global $theme;
+unset($theme);
+$theme=array();
+
 require_once('../config/config.php');
 require_once('../src/load_prefs.php');
 require_once('../functions/page_header.php');