Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY-19] Remove htaccess from allowed file types on new installations #13423

Merged
merged 1 commit into from
Apr 18, 2017

Conversation

Mark-H
Copy link
Collaborator

@Mark-H Mark-H commented Apr 17, 2017

Reported to security@modx.com by Anti Räis in ticket 19 and Tomáš Melicher in ticket 20, the ability to upload or create .htaccess files can cause code execution. In a way this is a feature, but it being enabled by default can pose a risk to users who are unaware that is possible.

Similar to how php files are not allowed out of the box, this patch will also prevent htaccess files by default. Users that want to manage htaccess from the manager can still do so by updating the upload_files setting after installation.

…tions

Reported to security@modx.com by Anti Räis in ticket 19 and Tomáš Melicher in ticket 20, the ability to upload or create .htaccess files can cause code execution. Similar to how php files are not allowed out of the box, this patch prevents htaccess files by default to protect against that. Users that want to manage htaccess from the manager can still do so by editing the upload_files setting after installation.
@rthrash
Copy link
Member

rthrash commented Aug 13, 2021

This pull request has been mentioned on MODX Community. There might be relevant details there:

https://community.modx.com/t/htaccess-has-a-lock-icon-on-it/4299/5

@Mark-H Mark-H deleted the security-19-htaccess branch August 13, 2021 11:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants