Skip to content
This repository was archived by the owner on Feb 7, 2025. It is now read-only.

Conversation

@jannejava
Copy link
Contributor

This pull request addresses a potential security issue in file handling where File::exists($path) was used to check if a file exists before serving it. Since File::exists() is based on PHP's file_exists() function, it also returns true for directories, which could lead to unintended behavior or vulnerabilities when directories are accessed instead of files.

@jannejava jannejava changed the title Update VoyagerController.php Enhance File Validation: Replace File::exists() with File::isFile() Nov 11, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant