mirror of
https://github.com/Dolibarr/dolibarr.git
synced 2026-01-05 16:42:53 +01:00
fix securite: Correction d'une faille de scurit sur le wrapper
This commit is contained in:
@@ -39,6 +39,9 @@ $original_file = urldecode($_GET["file"]);
|
||||
$modulepart = urldecode($_GET["modulepart"]);
|
||||
$type = urldecode($_GET["type"]);
|
||||
|
||||
//Suppression de la chaine de caract<63>re ../ dans $original_file
|
||||
$original_file = str_replace("../","/", "$original_file");
|
||||
|
||||
$accessallowed=0;
|
||||
if ($modulepart)
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user