mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
Fix upload filename traversal
Reject multipart filenames containing path separators before joining them to the selected upload path. This keeps LAN upload clients from creating files outside the selected directory.
This commit is contained in:
1 parent
c119d9b258
commit
2c3437940b
1 file changed
+7
-2
+7
-2
@@ -548,6 +548,11 @@ enum class MultiPartResult {
|
||||
Done,
|
||||
};
|
||||
|
||||
static bool IsSafeUploadFilename(std::string_view filename) {
|
||||
return !filename.empty() && filename != "." && filename != ".." &&
|
||||
filename.find_first_of("/\\") == std::string_view::npos;
|
||||
}
|
||||
|
||||
static MultiPartResult HandleMultipartPart(const http::ServerRequest &request, std::string boundary, const Path &uploadPath, ProgressTracker &progress) {
|
||||
std::string firstBoundary = request.In()->ReadLine();
|
||||
if (firstBoundary != "--" + boundary) {
|
||||
@@ -588,8 +593,8 @@ static MultiPartResult HandleMultipartPart(const http::ServerRequest &request, s
|
||||
}
|
||||
}
|
||||
|
||||
if (filename.empty()) {
|
||||
ERROR_LOG(Log::HTTP, "Didn't receive a filename");
|
||||
if (!IsSafeUploadFilename(filename)) {
|
||||
ERROR_LOG(Log::HTTP, "Invalid upload filename");
|
||||
return MultiPartResult::RequestError;
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user