[wp-trac] [WordPress Trac] #30377: wp_check_filetype is broken when checking urls with parameters

WordPress Trac noreply at wordpress.org
Tue Mar 8 13:57:49 UTC 2022


#30377: wp_check_filetype is broken when checking urls with parameters
-------------------------------------------------+-------------------------
 Reporter:  supercleanse                         |       Owner:  audrasjb
     Type:  enhancement                          |      Status:  reopened
 Priority:  normal                               |   Milestone:  6.0
Component:  Media                                |     Version:  4.0
 Severity:  normal                               |  Resolution:
 Keywords:  has-unit-tests needs-dev-note        |     Focuses:
  needs-patch                                    |
-------------------------------------------------+-------------------------

Comment (by SergeyBiryukov):

 As noted in comment:10, this was previously attempted in [30640] and
 reverted in [32171] as a security fix for
 [https://wordpress.org/news/2015/04/wordpress-4-1-2/ WordPress 4.1.2]. It
 would be great to confirm with the Security Team that [52829] does not
 reintroduce any issues.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/30377#comment:59>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list