mirror of
https://github.com/pandorafms/pandorafms.git
synced 2025-04-08 18:55:09 +02:00
Merge branch 'ent-12121-cve-2023-41814-xss-en-file-manager' into 'develop'
Ent 12121 cve 2023 41814 xss en file manager See merge request artica/pandorafms!6499
This commit is contained in:
commit
cd8652f9e6
@ -71,6 +71,8 @@ if (isset($config['filemanager']['message']) === true) {
|
||||
$fallback_directory = 'images';
|
||||
// Get directory.
|
||||
$directory = (string) get_parameter('directory');
|
||||
$directory = str_replace('<', '', $text);
|
||||
$directory = str_replace('>', '', $text);
|
||||
if (empty($directory) === true) {
|
||||
$directory = $fallback_directory;
|
||||
} else {
|
||||
|
Loading…
x
Reference in New Issue
Block a user