Skip to content
Permalink
Browse files Browse the repository at this point in the history
added allowed_classes=false param to unserialize func
  • Loading branch information
mariateresapomar committed Sep 26, 2022
1 parent b2aecbb commit d124b24
Show file tree
Hide file tree
Showing 3 changed files with 5 additions and 5 deletions.
2 changes: 1 addition & 1 deletion src/Controller/FrontPluginsController.php
Expand Up @@ -89,7 +89,7 @@ public function renderPluginModalAction()

$pluginHardcodedConfig = html_entity_decode($pluginHardcodedConfig, ENT_QUOTES);
$pluginHardcodedConfig = html_entity_decode($pluginHardcodedConfig, ENT_QUOTES);
$pluginHardcodedConfig = unserialize($pluginHardcodedConfig);
$pluginHardcodedConfig = unserialize($pluginHardcodedConfig, ['allowed_classes' => false]);

$errors = '';
$tag = '';
Expand Down
4 changes: 2 additions & 2 deletions src/Controller/SitesConfigController.php
Expand Up @@ -141,14 +141,14 @@ private function prepareDbConfigs($siteId, $siteName, &$dbConfigs)
if ($dbConfig['sconf_lang_id'] == '-1') {
$dbConfig['sconf_datas'] = [
'site' => [
$siteName => unserialize($dbConfig['sconf_datas'])
$siteName => unserialize($dbConfig['sconf_datas'], ['allowed_classes' => false])
],
];
} else {
$dbConfig['sconf_datas'] = [
'site' => [
$siteName => [
$siteId => unserialize($dbConfig['sconf_datas'])
$siteId => unserialize($dbConfig['sconf_datas'], ['allowed_classes' => false])
],
],
];
Expand Down
4 changes: 2 additions & 2 deletions src/Controller/SitesController.php
Expand Up @@ -1537,14 +1537,14 @@ private function prepareDbConfigs($siteId, $siteName, &$dbConfigs)
if ($dbConfig['sconf_lang_id'] == '-1') {
$dbConfig['sconf_datas'] = [
'site' => [
$siteName => unserialize($dbConfig['sconf_datas']),
$siteName => unserialize($dbConfig['sconf_datas'], ['allowed_classes' => false]),
],
];
} else {
$dbConfig['sconf_datas'] = [
'site' => [
$siteName => [
$siteId => unserialize($dbConfig['sconf_datas'])
$siteId => unserialize($dbConfig['sconf_datas'], ['allowed_classes' => false])
],
],
];
Expand Down

0 comments on commit d124b24

Please sign in to comment.