Uploaded image for project: 'phpBB'
  1. phpBB
  2. PHPBB-11331

Inform admin of incorrect avatar path instead of stripping unexpected parts from destination path

XMLWordPrintable

      When submitting an avatar the local avatar (gallery) path is stripped of the following unexpected content:

      $destination = str_replace(array('../', '..\\', './', '.\\'), '', $destination);

      This might lead to unexpected behavior. Either correctly handle those paths or inform the admin of an unexpepcted link when submitting the form with the settings.

            Marc Marc
            Marc Marc
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: