diff --git a/src/messenger/webim/libs/common.php b/src/messenger/webim/libs/common.php index f91fde5e..f6cc16e5 100644 --- a/src/messenger/webim/libs/common.php +++ b/src/messenger/webim/libs/common.php @@ -702,7 +702,7 @@ function csrfchecktoken(){ die("CSRF failure"); } - } else if($_GET['act'] == 'del' && $_GET['csrf_token'] != $_SESSION['csrf_token']){ + } else if(($_GET['act'] == 'del' || $_GET['act'] == 'delete') && $_GET['csrf_token'] != $_SESSION['csrf_token']){ die("CSRF failure"); } diff --git a/src/messenger/webim/operator/canned.php b/src/messenger/webim/operator/canned.php index 9d9f7886..d326f032 100644 --- a/src/messenger/webim/operator/canned.php +++ b/src/messenger/webim/operator/canned.php @@ -25,6 +25,8 @@ require_once('../libs/settings.php'); require_once('../libs/groups.php'); require_once('../libs/pagination.php'); +csrfchecktoken(); + $operator = check_login(); loadsettings(); diff --git a/src/messenger/webim/view/canned.php b/src/messenger/webim/view/canned.php index 3863aac8..6caee93b 100644 --- a/src/messenger/webim/view/canned.php +++ b/src/messenger/webim/view/canned.php @@ -91,7 +91,7 @@ if( $page['pagination.items'] ) {