From 14611f3f7aa2be01b77c84aa46e9cbc6d02ff7dd Mon Sep 17 00:00:00 2001 From: Laurent Destailleur Date: Fri, 19 Mar 2021 12:49:28 +0100 Subject: [PATCH] More complete protection for doprev donext, dvprev, dvnext action. --- htdocs/main.inc.php | 1 + 1 file changed, 1 insertion(+) diff --git a/htdocs/main.inc.php b/htdocs/main.inc.php index 108a25e1877..019e30dca25 100644 --- a/htdocs/main.inc.php +++ b/htdocs/main.inc.php @@ -436,6 +436,7 @@ if ((!defined('NOCSRFCHECK') && empty($dolibarr_nocsrfcheck) && !empty($conf->gl 'activate', 'add', 'addtimespent', 'update', 'install', 'confirm_create_user', 'confirm_create_thirdparty', 'confirm_reject_check', 'delete', 'deletefilter', 'deleteoperation', 'deleteprof', 'deletepayment', 'disable', + 'doprev', 'donext', 'dvprev', 'dvnext', 'enable' ); $sensitiveget = false;