This is the actual security fix

This commit is contained in:
slawkens 2021-07-05 02:59:41 +02:00
parent aa26a71949
commit a2a773d714

View File

@ -334,7 +334,7 @@ if($load_it)
}
} else {
$file = SYSTEM . 'pages/' . $page . '.php';
if(!@file_exists($file))
if(!@file_exists($file) || preg_match('/[^A-z0-9_\-]/', $page))
{
$page = '404';
$file = SYSTEM . 'pages/404.php';