Incomplete path check, when delete a gallery
-
Hello,
the commit 1dfa461 contains an incomplete fix. If you put accidentally ‘../’ as gallery path, which should also resolved by realpath(), it will resolve into an directory outside the get_document_root(). Then unlink deletes the whole wordpress. You should give the user a hint, setting such a path is dangerous.
HTH
Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
- The topic ‘Incomplete path check, when delete a gallery’ is closed to new replies.