Merge pull request #257 from Fraenkiman/upstream/issue217-Vulnerability-Stored-XSS-

Prevents upload of files with .xsig extension
This commit is contained in:
Arvid Zimmermann 2023-09-02 12:13:56 +02:00 committed by GitHub
commit d49c2c40b8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -99,7 +99,8 @@ class admin_uploader_default extends AdminPanelAction {
'svg', 'svg',
'xml', 'xml',
'md', 'md',
'pages' 'pages',
'xsig'
); );
$imgs = array( $imgs = array(