From 915db857b8dcf54e697cb9490883da53fd83cbcb Mon Sep 17 00:00:00 2001 From: tjhunt Date: Sun, 13 Aug 2006 20:25:46 +0000 Subject: [PATCH] SC 289, small, but non-exploitable hole in backup permissions checking. --- backup/backup.php | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/backup/backup.php b/backup/backup.php index 703e77b577b..88fcdad8173 100644 --- a/backup/backup.php +++ b/backup/backup.php @@ -17,13 +17,7 @@ if (!empty($id)) { if (!isteacheredit($id)) { - if (empty($to)) { - error("You need to be a teacher or admin user to use this page.", "$CFG->wwwroot/login/index.php"); - } else { - if (!isteacheredit($to)) { - error("You need to be a teacher or admin user to use this page.", "$CFG->wwwroot/login/index.php"); - } - } + error("You need to be a teacher or admin user to use this page.", "$CFG->wwwroot/login/index.php"); } } else { if (!isadmin()) { @@ -31,6 +25,12 @@ } } + if (!empty($to)) { + if (!isteacheredit($to)) { + error("You need to be a teacher or admin user to use this page.", "$CFG->wwwroot/login/index.php"); + } + } + //Check site if (!$site = get_site()) { error("Site not found!"); @@ -128,7 +128,7 @@ } print_simple_box_end(); - //Print footer + //Print footer print_footer(); ?>