Skip to content

Commit f5fc41e

Browse files
committed
SECURITY: prevent directory traversal vulnerability.
1 parent 4ad07d7 commit f5fc41e

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

lib/Horde/Form/Type.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1205,7 +1205,7 @@ function _getUpload(&$vars, &$var)
12051205
/* Get the temp file if already one uploaded, otherwise create a
12061206
* new temporary file. */
12071207
if (!empty($upload['img']['file'])) {
1208-
$tmp_file = Horde::getTempDir() . '/' . $upload['img']['file'];
1208+
$tmp_file = Horde::getTempDir() . '/' . basename($upload['img']['file']);
12091209
} else {
12101210
$tmp_file = Horde::getTempFile('Horde', false);
12111211
}

0 commit comments

Comments
 (0)