Homestyx hydra
Diffusion hydra 2037979142cb

Prevent Phame blogs from using invalid skins

Description

Prevent Phame blogs from using invalid skins

Summary: Via HackerOne. An attacker with access to both Phame and the filesystem could potentially load a skin that lives outside of the configured skin directories, because we had insufficient checks on the actual skin at load time.

Test Plan: Attempted to build a blog with an invalid skin; got an exception instead of a mis-load of a sketchy skin.

Reviewers: btrahan

Reviewed By: btrahan

Subscribers: epriestley

Differential Revision: https://secure.phabricator.com/D10992

Details

Provenance
epriestleyAuthored on Dec 15 2014, 1:41 PM
sirocylPushed on Oct 16 2024, 5:49 AM
Parents
R1:2a9db94ba6e9: Restore Maniphest subscriber transaction mail tag
Branches
Unknown
Tags
Unknown

Event Timeline