Skip to content

Commit 15e49c1

Browse files
committed
Add default value for search_users (path disclosure) - refs #2746
1 parent da8a93e commit 15e49c1

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

Diff for: main/admin/dashboard_add_users_to_user.php

+2-1
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@
6363
api_not_allowed(true);
6464
}
6565

66-
function search_users($needle, $type)
66+
function search_users($needle, $type = 'multiple')
6767
{
6868
global $tbl_access_url_rel_user, $tbl_user, $user_anonymous, $current_user_id, $user_id, $userStatus;
6969

@@ -365,6 +365,7 @@ function remove_item(origin) {
365365
}
366366

367367
$search_user = '';
368+
$needle = '';
368369
if (!empty($firstLetterUser)) {
369370
$needle = Database::escape_string($firstLetterUser);
370371
$search_user = "AND ".(api_sort_by_first_name() ? 'firstname' : 'lastname')." LIKE '$needle%'";

0 commit comments

Comments
 (0)