diff --git a/pandora_console/operation/reporting/graph_viewer.php b/pandora_console/operation/reporting/graph_viewer.php
index c518598f38..7584396778 100644
--- a/pandora_console/operation/reporting/graph_viewer.php
+++ b/pandora_console/operation/reporting/graph_viewer.php
@@ -29,18 +29,24 @@ if (comprueba_login() != 0) {
// Delete module SQL code
if (isset($_GET["delete"])){
- $id = $_GET["delete"];
- $sql = "DELETE FROM tgraph_source WHERE id_graph = $id";
- if ($res=mysql_query($sql))
- $result = "
".$lang_label["delete_ok"]."
";
- else
- $result = "".$lang_label["delete_no"]."
";
- $sql = "DELETE FROM tgraph WHERE id_graph = $id";
- if ($res=mysql_query($sql))
- $result = "".$lang_label["delete_ok"]."
";
- else
- $result = "".$lang_label["delete_no"]."
";
- echo $result;
+ if ((give_acl($id_usuario,0,"AW") == 1 ) OR (dame_admin($id_user)==1)) {
+ $id = $_GET["delete"];
+ $sql = "DELETE FROM tgraph_source WHERE id_graph = $id";
+ if ($res=mysql_query($sql))
+ $result = "".$lang_label["delete_ok"]."
";
+ else
+ $result = "".$lang_label["delete_no"]."
";
+ $sql = "DELETE FROM tgraph WHERE id_graph = $id";
+ if ($res=mysql_query($sql))
+ $result = "".$lang_label["delete_ok"]."
";
+ else
+ $result = "".$lang_label["delete_no"]."
";
+ echo $result;
+ } else {
+ audit_db($id_usuario,$REMOTE_ADDR, "ACL Violation","Trying to delete a graph from access graph builder");
+ include ("general/noaccess.php");
+ exit;
+ }
}
@@ -143,7 +149,7 @@ echo "".$lang_label["reporting"]." > ";
echo $lang_label["custom_graph_viewer"]."
";
echo "";
echo "".$lang_label["graph_name"]." | ".$lang_label["description"]." | ".$lang_label["view"];
-if ((give_acl($id_usuario,0,"AW") == 1 ) OR (dame_admin($id_user)==1))
+if ((give_acl($id_usuario,0,"AW") == 1 ) OR (dame_admin($id_usuario)==1))
echo " | ";
$color=1;
@@ -166,7 +172,7 @@ while ($row = mysql_fetch_array($res)){
$id_graph = $row["id_graph"];
echo " | ";
- if ((give_acl($id_usuario,0,"AW") == 1 ) OR (dame_admin($id_user)==1)) {
+ if ((give_acl($id_usuario,0,"AW") == 1 ) OR (dame_admin($id_usuario)==1)) {
echo " | ';
echo "![](images/cross.png) | ";
}
---|