Skip to content
This repository was archived by the owner on Feb 7, 2025. It is now read-only.

Enhance File Validation: Replace File::exists() with File::isFile() #5929

Open
wants to merge 1 commit into
base: 1.7
Choose a base branch
from

Conversation

jannejava
Copy link
Contributor

This pull request addresses a potential security issue in file handling where File::exists($path) was used to check if a file exists before serving it. Since File::exists() is based on PHP's file_exists() function, it also returns true for directories, which could lead to unintended behavior or vulnerabilities when directories are accessed instead of files.

@jannejava jannejava changed the title Update VoyagerController.php Enhance File Validation: Replace File::exists() with File::isFile() Nov 11, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant