fix major security issue

This commit is contained in:
Uwe Steinmann 2021-02-25 12:04:27 +01:00
parent 35702a30b4
commit 9d8654c183

View File

@ -39,7 +39,7 @@ if(true) {
$file = substr($uri->getPath(), 1); $file = substr($uri->getPath(), 1);
if(file_exists($file) && is_file($file)) { if(file_exists($file) && is_file($file)) {
$_SERVER['SCRIPT_FILENAME'] = basename($file); $_SERVER['SCRIPT_FILENAME'] = basename($file);
include($file); // include($file);
exit; exit;
} }
if($request->isXhr()) { if($request->isXhr()) {