From 86620cf2ae3108253f01d20da561b5a524944081 Mon Sep 17 00:00:00 2001 From: ThaaoBlues Date: Tue, 4 Nov 2025 21:34:52 +0100 Subject: [PATCH] fix : user listing leak --- bdd.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/bdd.php b/bdd.php index f68ec59..78d4265 100644 --- a/bdd.php +++ b/bdd.php @@ -237,7 +237,7 @@ function RechercheExercices($query, $length, $tags, $tout_les_insa) global $conn; // Start with the base SQL query - $sql = "SELECT * FROM documents AS d INNER JOIN ensembles AS e ON d.ensemble_id = e.id JOIN users as u ON u.id=e.id_auteur WHERE e.valide=TRUE"; + $sql = "SELECT d.titre,d.type,d.upload_path, FROM documents AS d INNER JOIN ensembles AS e ON d.ensemble_id = e.id JOIN (SELECT id,username FROM users) as u ON u.id=e.id_auteur WHERE e.valide=TRUE"; // Array to hold the parameters $params = [];