Commit 6fb8eaa
committed
Fixed rename failing to prevent rename to restricted file extension in media library, 'Remote Code Execution via Chained Rename Bypass and .htaccess PHP Handler Injection', reported by @kdalal-vulncheck #419
1 parent 23ac0e8 commit 6fb8eaa
1 file changed
Lines changed: 5 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
205 | 205 | | |
206 | 206 | | |
207 | 207 | | |
| 208 | + | |
| 209 | + | |
208 | 210 | | |
209 | 211 | | |
210 | 212 | | |
| |||
217 | 219 | | |
218 | 220 | | |
219 | 221 | | |
220 | | - | |
221 | | - | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
222 | 225 | | |
223 | 226 | | |
224 | 227 | | |
| |||
235 | 238 | | |
236 | 239 | | |
237 | 240 | | |
238 | | - | |
239 | 241 | | |
240 | 242 | | |
241 | 243 | | |
| |||
0 commit comments