[wp-trac] [WordPress Trac] #48316: Changeset 46482 breaks upload when using ".." in upload_path.
WordPress Trac
noreply at wordpress.org
Mon Oct 21 19:15:59 UTC 2019
#48316: Changeset 46482 breaks upload when using ".." in upload_path.
----------------------------+---------------------
Reporter: xpoon | Owner: (none)
Type: defect (bug) | Status: new
Priority: normal | Milestone: 5.2.5
Component: Filesystem API | Version: trunk
Severity: major | Resolution:
Keywords: | Focuses:
----------------------------+---------------------
Comment (by Clorith):
Hi there, and welcome to WordPress trac!
You're right that the changeset mentioned made the path traversals
stricter, I noticed you're referring to a relative path for your uploads
folder though.
Would you be able to use an absolute path here instead, as that should
avoid the stricter path rules?
--
Ticket URL: <https://core.trac.wordpress.org/ticket/48316#comment:5>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform
More information about the wp-trac
mailing list