1
0
mirror of https://github.com/prasathmani/tinyfilemanager.git synced 2025-06-25 20:42:51 +02:00

Deploy path traversal fix ()

Co-authored-by: root <root@chevaliers.lan>
This commit is contained in:
minghongg
2023-01-25 13:16:20 +07:00
committed by GitHub
parent dd1ba6795c
commit cddd7eaab0

@ -1065,6 +1065,15 @@ if (isset($_POST['group'], $_POST['token']) && (isset($_POST['zip']) || isset($_
}
$files = $_POST['file'];
$sanitized_files = array();
// clean path
foreach($files as $file){
array_push($sanitized_files, fm_clean_path($file));
}
$files = $sanitized_files;
if (!empty($files)) {
chdir($path);