Skip to content

Avoid Arbitrary File Deletion abuse via Object Injection#226

Merged
JamesHeinrich merged 1 commit intoJamesHeinrich:masterfrom
mcdruid:object-injection-hardening
Nov 22, 2024
Merged

Avoid Arbitrary File Deletion abuse via Object Injection#226
JamesHeinrich merged 1 commit intoJamesHeinrich:masterfrom
mcdruid:object-injection-hardening

Conversation

@mcdruid
Copy link
Copy Markdown
Contributor

@mcdruid mcdruid commented Nov 22, 2024

Try to check temp file is really a pThumb temp file before deleting it, to avoid abuse via Object Injection.

@JamesHeinrich JamesHeinrich merged commit 0c87fde into JamesHeinrich:master Nov 22, 2024
@opengeek
Copy link
Copy Markdown

@JamesHeinrich — is there any possibility we can get a new release with this in it?

@JamesHeinrich
Copy link
Copy Markdown
Owner

https://github.com/JamesHeinrich/phpThumb/releases/tag/v1.7.23

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants