We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 7ca153f commit 9d0349dCopy full SHA for 9d0349d
Http/Controllers/Backend/MediaController.php
@@ -356,6 +356,12 @@ public function upload(Request $request): JsonResponse
356
$request->folder_path = $request->folder_path."/".date('Y')."/".date('m');
357
}
358
359
+ if (Str::contains($request->folder_path, ['..', '\\'])) {
360
+ $response['success'] = false;
361
+ $response['errors'][] = 'Invalid folder path "'.$request->folder_path.'"';
362
+ return response()->json($response);
363
+ }
364
+
365
$data['extension'] = $request->file($input_file_name)->extension();
366
$data['original_name'] = $request->file($input_file_name)->getClientOriginalName();
367
$data['mime_type'] = $request->file($input_file_name)->getClientMimeType();
0 commit comments