관리자 권한 문맥 오염 계열 접근권한 점검 및 보완
게시판/그룹 관리자 문맥(bo_table)으로 타 회원 콘텐츠에 접근·변조되지 않도록 $is_admin 판정을 최고관리자(super) 기준으로 통일. - bbs/poll_etc_update.php : 설문 기타의견 삭제 소유권 - shop/itemqaformupdate.php : 상품문의 수정/삭제 소유권 - shop/itemuseformupdate.php : 사용후기 삭제 소유권 - bbs/current_connect.php : 게스트 IP 원본 표기 - shop/kakaopay/kakaopay_cancel.php : TID 기반 결제취소 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> (cherry picked from commit 46a005129464d1fbab518fcb70bf524b258e65fc)
This commit is contained in:
@@ -57,7 +57,7 @@ if ($w == "")
|
||||
}
|
||||
else if ($w == "u")
|
||||
{
|
||||
if (!$is_admin)
|
||||
if ($is_admin !== 'super')
|
||||
{
|
||||
$sql = " select count(*) as cnt from {$g5['g5_shop_item_qa_table']} where mb_id = '{$member['mb_id']}' and iq_id = '$iq_id' ";
|
||||
$row = sql_fetch($sql);
|
||||
@@ -86,7 +86,7 @@ else if ($w == "u")
|
||||
}
|
||||
else if ($w == "d")
|
||||
{
|
||||
if (!$is_admin)
|
||||
if ($is_admin !== 'super')
|
||||
{
|
||||
$sql = " select iq_answer from {$g5['g5_shop_item_qa_table']} where mb_id = '{$member['mb_id']}' and iq_id = '$iq_id' ";
|
||||
$row = sql_fetch($sql);
|
||||
|
||||
@@ -91,7 +91,7 @@ else if ($w == "u")
|
||||
}
|
||||
else if ($w == "d")
|
||||
{
|
||||
if (!$is_admin)
|
||||
if ($is_admin !== 'super')
|
||||
{
|
||||
$sql = " select count(*) as cnt from {$g5['g5_shop_item_use_table']} where mb_id = '{$member['mb_id']}' and is_id = '$is_id' ";
|
||||
$row = sql_fetch($sql);
|
||||
|
||||
@@ -50,7 +50,7 @@ if($cancelFlag == "true")
|
||||
$db_check = 1;
|
||||
$cancel_msg = "DB FAIL";
|
||||
|
||||
if( $is_admin ){
|
||||
if( $is_admin === 'super' ){
|
||||
$tmp = sql_fetch("select * from `{$g5['g5_shop_order_table']}` where od_tno = '".trim($_REQUEST['TID'])."' ");
|
||||
|
||||
if( $tmp['od_pg'] === 'KAKAOPAY' ){
|
||||
|
||||
Reference in New Issue
Block a user