Commit 8f3b0a3c authored by dsnopek's avatar dsnopek Committed by dsnopek

Issue #2870804 by dsnopek: [cck] Fix for SA-CONTRIB-2017-038

parent 0a05e348
diff --git a/modules/nodereference/nodereference.module b/modules/nodereference/nodereference.module
index 5969a4f..0170cf1 100644
--- a/modules/nodereference/nodereference.module
+++ b/modules/nodereference/nodereference.module
@@ -935,6 +935,10 @@ function _nodereference_potential_references_standard($field, $string = '', $mat
return array();
}
+ if (!user_access('administer nodes')) {
+ $where[] = 'n.status = 1';
+ }
+
if ($string !== '') {
$like = $GLOBALS["db_type"] == 'pgsql' ? "ILIKE" : "LIKE";
$match_clauses = array(
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment