grav
grav copied to clipboard
Avoid Arbitrary File Deletion abuse via Object Injection
As discussed with @rhukster this simple change should avoid \Grav\Framework\Cache\Adapter\FileCache::__destruct being abused via Object Injection to achieve Arbitrary File Deletion.
I've used strpos rather than str_starts_with as it looks like Grav supports PHP 7.
@codex review