Uploaded image for project: 'phpBB3'
  1. phpBB3
  2. PHPBB3-15865

Local avatar driver CHECKED value is wrong due to mismatched URL encoding

    XMLWordPrintable

Details

    • Bug
    • Status: Open (View Workflow)
    • Minor
    • Resolution: Unresolved
    • 3.2.3
    • None
    • None
    • None

    Description

      In phpbb\avatar\driver\local, $img['file'] and $row['avatar'] are compared to determine whether or not a given local avatar is the current user’s avatar. $img['file'] is partially URL encoded and $row['avatar'] is not, so these comparisons fail whenever the avatar’s filename or path contains characters that are not in the range [0-9a-fA-F_.~-].

      Attachments

        Activity

          People

            Unassigned Unassigned
            Snover Snover [X] (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: