?
avatar ceford
ceford
28 Nov 2020

Steps to reproduce the issue

Look at code: libraries/Helper/MediaHelper.php line 300

$xss_check = file_get_contents($file['tmp_name'], false, null, -1, 256);

It makes no sense to me. It reads in the last character so none of the following tag tests can ever find a tag.

If terminated after the file name it can successfully reject a bad svg file.

$xss_check = file_get_contents($file['tmp_name']);//, false, null, -1, 256);

Can someone explain?

Expected result

Actual result

System information (as much as possible)

Additional comments

avatar ceford ceford - open - 28 Nov 2020
avatar joomla-cms-bot joomla-cms-bot - labeled - 28 Nov 2020
avatar ceford ceford - change - 28 Nov 2020
The description was changed
avatar ceford ceford - edited - 28 Nov 2020
avatar bembelimen bembelimen - change - 28 Dec 2020
Status New Closed
Closed_Date 0000-00-00 00:00:00 2020-12-28 01:00:33
Closed_By bembelimen
avatar bembelimen bembelimen - close - 28 Dec 2020

Add a Comment

Login with GitHub to post a comment