mirror of
https://github.com/BookStackApp/BookStack.git
synced 2025-05-23 23:29:59 +08:00
Added extension whitelist for image uploads
- A continuation of the security issues addressed in v0.25.3
This commit is contained in:
@ -119,7 +119,7 @@ class ImageController extends Controller
|
||||
{
|
||||
$this->checkPermission('image-create-all');
|
||||
$this->validate($request, [
|
||||
'file' => 'mimes:jpeg,png,gif,bmp,webp,tiff'
|
||||
'file' => 'image_extension|mimes:jpeg,png,gif,bmp,webp,tiff'
|
||||
]);
|
||||
|
||||
if (!$this->imageRepo->isValidType($type)) {
|
||||
|
Reference in New Issue
Block a user