From 3c9cc69364a45fd3f92d4bd606344b5dd1205d6a Mon Sep 17 00:00:00 2001 From: Fraenkiman Date: Sat, 29 Jul 2023 13:12:30 +0200 Subject: [PATCH] Prevents upload of files with .xsig extension Fixes Vulnerability Stored XSS #217 --- admin/panels/uploader/admin.uploader.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/admin/panels/uploader/admin.uploader.php b/admin/panels/uploader/admin.uploader.php index e307479..ca3e813 100755 --- a/admin/panels/uploader/admin.uploader.php +++ b/admin/panels/uploader/admin.uploader.php @@ -99,7 +99,8 @@ class admin_uploader_default extends AdminPanelAction { 'svg', 'xml', 'md', - 'pages' + 'pages', + 'xsig' ); $imgs = array(