By submitting values for the global variable $user, an attacker can cause PHP to execute an SQL query which makes changes to display settings for a specific target user.
By submitting values for the global variable $user, an attacker can cause PHP to execute an SQL query which makes changes to display settings for a specific target user.