BUG-15029 Improvement called function Rename Folder broked the security
This commit is contained in:
@@ -21,6 +21,8 @@ if (! isset ($_REQUEST ['action'])) {
|
|||||||
die ();
|
die ();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
$_REQUEST['action'] = ($_REQUEST['action'] == 'rename') ? 'renameFolder' : $_REQUEST['action'];
|
||||||
|
|
||||||
if (! function_exists ($_REQUEST['action']) || !G::isUserFunction($_REQUEST['action'])) {
|
if (! function_exists ($_REQUEST['action']) || !G::isUserFunction($_REQUEST['action'])) {
|
||||||
$res ['success'] = false;
|
$res ['success'] = false;
|
||||||
$res ['message'] = 'The requested action does not exist';
|
$res ['message'] = 'The requested action does not exist';
|
||||||
@@ -28,7 +30,7 @@ if (! function_exists ($_REQUEST['action']) || !G::isUserFunction($_REQUEST['act
|
|||||||
die ();
|
die ();
|
||||||
}
|
}
|
||||||
|
|
||||||
if (($_REQUEST['action']) != 'rename') {
|
if (($_REQUEST['action']) != 'renameFolder') {
|
||||||
$functionName = $_REQUEST ['action'];
|
$functionName = $_REQUEST ['action'];
|
||||||
$functionParams = isset ($_REQUEST ['params']) ? $_REQUEST ['params'] : array ();
|
$functionParams = isset ($_REQUEST ['params']) ? $_REQUEST ['params'] : array ();
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user