Deploy path traversal fix (#953)

Co-authored-by: root <root@chevaliers.lan>
This commit is contained in:
minghongg 2023-01-25 13:16:20 +07:00 committed by GitHub
parent dd1ba6795c
commit cddd7eaab0
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -1065,6 +1065,15 @@ if (isset($_POST['group'], $_POST['token']) && (isset($_POST['zip']) || isset($_
}
$files = $_POST['file'];
$sanitized_files = array();
// clean path
foreach($files as $file){
array_push($sanitized_files, fm_clean_path($file));
}
$files = $sanitized_files;
if (!empty($files)) {
chdir($path);