grav icon indicating copy to clipboard operation
grav copied to clipboard

Avoid Arbitrary File Deletion abuse via Object Injection

Open mcdruid opened this issue 1 year ago • 1 comments

As discussed with @rhukster this simple change should avoid \Grav\Framework\Cache\Adapter\FileCache::__destruct being abused via Object Injection to achieve Arbitrary File Deletion.

I've used strpos rather than str_starts_with as it looks like Grav supports PHP 7.

mcdruid avatar Dec 03 '24 17:12 mcdruid

@codex review

rhukster avatar Oct 16 '25 14:10 rhukster