From 1770f28deeed30e00a8d9c7c2041bbf894e29e54 Mon Sep 17 00:00:00 2001 From: Garvin Hicking Date: Tue, 21 Aug 2007 15:54:25 +0000 Subject: [PATCH] array check, thanks to phellmes --- include/admin/personal.inc.php | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/include/admin/personal.inc.php b/include/admin/personal.inc.php index ed970a1b..78d83bed 100644 --- a/include/admin/personal.inc.php +++ b/include/admin/personal.inc.php @@ -32,7 +32,10 @@ if ($serendipity['GET']['adminAction'] == 'save' && serendipity_checkFormToken() // Void, no fixing neccessarry } elseif (serendipity_checkPermission('adminUsersMaintainSame')) { - + if (!is_array($_POST[$item['var']])) { + continue; + } + // Check that no user may assign groups he's not allowed to. foreach($_POST[$item['var']] AS $groupkey => $groupval) { if (in_array($groupval, $valid_groups)) {