Fix RVE-2023-5

This commit is contained in:
Kijin Sung 2023-09-26 19:57:22 +09:00
parent a4b49048f3
commit 7e018573b9

View file

@ -259,7 +259,7 @@ class communicationView extends communication
if($message_srl)
{
$source_message = $oCommunicationModel->getSelectedMessage($message_srl);
if($source_message->message_srl == $message_srl && $source_message->sender_srl == $receiver_srl)
if($source_message->message_srl == $message_srl && $source_message->sender_srl == $receiver_srl && $source_message->receiver_srl == $logged_info->member_srl)
{
if(strncasecmp('[re]', $source_message->title, 4) !== 0)
{