This commit is contained in:
qronald
2017-05-31 14:28:37 -04:00
committed by Julio Cesar Laura Avendaño
parent d76446a0cc
commit 3a26dce3a0

View File

@@ -152,7 +152,7 @@ class FilesManager
{
try {
$aData['prf_path'] = rtrim($aData['prf_path'], '/') . '/';
if (!$aData['prf_filename']) {
if (!$aData['prf_filename'] || strpbrk($aData['prf_filename'], "\\/?%*:|\"<>") !== false) {
throw new \Exception(\G::LoadTranslation("ID_INVALID_VALUE_FOR", array('prf_filename')));
}
$extention = strstr($aData['prf_filename'], '.');