Skip to content
Permalink
Browse files

Protect lp_upload.php to avoid malicious uploads by unauthenticated u…

…sers #security
  • Loading branch information...
ywarnier committed Feb 23, 2019
1 parent e463775 commit 1c82459f142e67636b9241cef1d46b2b927547dd
Showing with 1 addition and 2 deletions.
  1. +1 −2 main/lp/lp_upload.php
@@ -12,9 +12,8 @@
* @author Yannick Warnier <ywarnier@beeznest.org>
*/
// Flag to allow for anonymous user - needs to be set before global.inc.php.
$use_anonymous = true;
require_once __DIR__.'/../inc/global.inc.php';
api_protect_course_script();
$course_dir = api_get_course_path().'/scorm';
$course_sys_dir = api_get_path(SYS_COURSE_PATH).$course_dir;
if (empty($_POST['current_dir'])) {

0 comments on commit 1c82459

Please sign in to comment.
You can’t perform that action at this time.