HEX
Server: Apache/2.4.58 (Ubuntu)
System: Linux host 6.8.0-107-generic #107-Ubuntu SMP PREEMPT_DYNAMIC Fri Mar 13 19:51:50 UTC 2026 x86_64
User: w230 (1248)
PHP: 8.3.6
Disabled: NONE
Upload Files
File: /var/www/w230/html/hwnapp/admin/user_edit_password.php
<?php
require_once('../connections/mysqli.php');

if ($_SESSION == NULL) {
  header("location:../login.php");
  exit();
}elseif ($_SESSION["user_level"] != "admin") {
  header("location:../index.php");
  exit();
}

$id = $_POST["id"];

$sql = "UPDATE tb_user SET user_password = '".md5($_POST['user_password'])."' WHERE user_id = '".$id."'";
$query = mysqli_query($Connection,$sql);

header("location:user.php?update=pass");
exit();

mysqli_close($Connection);
?>