mirror of
https://github.com/pandorafms/pandorafms.git
synced 2025-07-31 01:35:36 +02:00
Prepend folder to image to avoid Phar injection
This commit is contained in:
parent
475517afd7
commit
ca35bb64cc
@ -57,6 +57,9 @@ switch ($graph_type) {
|
|||||||
$out_of_lim_str = io_safe_output(get_parameter('out_of_lim_str', false));
|
$out_of_lim_str = io_safe_output(get_parameter('out_of_lim_str', false));
|
||||||
$out_of_lim_image = get_parameter('out_of_lim_image', false);
|
$out_of_lim_image = get_parameter('out_of_lim_image', false);
|
||||||
|
|
||||||
|
// Add relative path to avoid phar object injection.
|
||||||
|
$out_of_lim_image = '../graphs/'.$out_of_lim_image;
|
||||||
|
|
||||||
$title = get_parameter('title');
|
$title = get_parameter('title');
|
||||||
|
|
||||||
$mode = get_parameter('mode', 1);
|
$mode = get_parameter('mode', 1);
|
||||||
|
Loading…
x
Reference in New Issue
Block a user