From ffe379addebcd980399502f31ecdb81e235b1ca5 Mon Sep 17 00:00:00 2001 From: jim-p Date: Fri, 10 May 2019 15:28:27 -0400 Subject: [PATCH] Strengthen path privilege check. Fixes #9513 * Removes/resolves any relative paths in the submitted URL * Validates that the file exists * Trims the path component off after in a nicer way (cherry picked from commit 0604f68855ff65b92cdebd57a08a2ceccbef675c) --- src/etc/inc/auth_func.inc | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/src/etc/inc/auth_func.inc b/src/etc/inc/auth_func.inc index f1536d4416..5bdee86901 100644 --- a/src/etc/inc/auth_func.inc +++ b/src/etc/inc/auth_func.inc @@ -30,6 +30,7 @@ function cmp_page_matches($page, & $matches, $fullwc = true) { + global $g; // $dbg_matches = implode(",", $matches); // log_error("debug: checking page {$page} match with {$dbg_matches}"); @@ -37,11 +38,14 @@ function cmp_page_matches($page, & $matches, $fullwc = true) { return false; } - /* skip any leading fwdslash */ - $test = strpos($page, "/"); - if ($test !== false && $test == 0) { - $page = substr($page, 1); + list($file, $query) = explode('?', $page); + $file = realpath( $g['www_path'] . '/' . ltrim($file, '/')); + if (empty($file)) { + /* File does not exist, or other path shenanigans */ + return false; } + $page = str_replace($g['www_path'] . '/', '', $file); + $page .= (!empty($query)) ? "?{$query}" : ""; /* look for a match */ foreach ($matches as $match) {