Merge remote-tracking branch 'marc1706/master'
This commit is contained in:
@@ -112,7 +112,8 @@ class portal_upload
|
|||||||
$cur_path = str_replace($mod_dir . '/', '', $cur_path);
|
$cur_path = str_replace($mod_dir . '/', '', $cur_path);
|
||||||
$cut_pos = strpos($cur_path, '/');
|
$cut_pos = strpos($cur_path, '/');
|
||||||
|
|
||||||
if(!in_array(substr($cur_path, 0, $cut_pos), array('portal', 'language', 'styles')))
|
// Only allow files in adm, language, portal and styles folder
|
||||||
|
if(!in_array(substr($cur_path, 0, $cut_pos), array('adm', 'language', 'portal', 'styles')))
|
||||||
{
|
{
|
||||||
$file->remove();
|
$file->remove();
|
||||||
$this->directory_delete($mod_dir);
|
$this->directory_delete($mod_dir);
|
||||||
|
|||||||
Reference in New Issue
Block a user