Details
-
Bug
-
Resolution: Invalid
-
None
-
Critical
-
NONE: Issue was already solved as side-effect of implementing BCONF-Management Milestone 2
-
Empty show more show less
Description
problem
An uploaded bconf file could be modified in a way, so that the contained SRX files are not written to the data/editorOkapiBconf/ but somewhere outside.
solution
check the final path of the created file and restrict so the save file location. And/or use basename to get just the filename part of the file and use that.