Project

General

Profile

Actions

Bug #60173

closed

fileDenyPattern is not respected for admins on renaming files

Added by Manuel Wohlers over 10 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Could have
Assignee:
-
Category:
File Abstraction Layer (FAL)
Target version:
-
Start date:
2014-07-08
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
6.2
PHP Version:
Tags:
Complexity:
medium
Is Regression:
No
Sprint Focus:

Description

The configured fileDenyPattern is not respected on rename:

A file can be uploaded as "test.jpg" and renamed to "test.php" in the Filelist in Typo3 Backend. Thereafter the php file can be executed.

Verified in Typo3 CMS 6.1.5 and 6.2.3


Related issues 1 (0 open1 closed)

Has duplicate TYPO3 Core - Bug #64619: Different behavior of allowed filename for adminsClosed2015-01-29

Actions
Actions

Also available in: Atom PDF