Bug #64619
closedDifferent behavior of allowed filename for admins
0%
Description
It is not possible to upload a file in the filelistmodule that has an extension that is in $GLOBALS['TYPO3_CONF_VARS']['BE']['fileDenyPattern']
.
The file typo3/tce_file.php
, that is used for TCA Uploads, allows uploading of files with a non allowed file extension.
Reproduce: Create a content element of type "File links", Click on the "Add File" button, select a php file and hit "upload files".
As discussed with the Security Team this is not an security issue as admins are always able to upload files that are executable (like extensions).
The behavior should be the same for all uploads.
Files
Updated by Sascha Egerer almost 10 years ago
- Status changed from Accepted to In Progress
- Assignee set to Sascha Egerer
Updated by Armin Vieweg almost 10 years ago
As editor I am not able to upload a file with denied file extension. Not in Flash uploader, nor in Element Browser popup.
So this ticket seems to be obsolete.
Updated by Armin Vieweg almost 10 years ago
- File 2015-01-31_1756.png 2015-01-31_1756.png added
- File 2015-01-31_1757.png 2015-01-31_1757.png added
Updated by Sascha Egerer almost 10 years ago
The Ticket is about an admin user.
An admin is able to upload a php file in a content element but not in the filelist module. It shouldn't be possible at both places.
Updated by Gerrit Code Review almost 10 years ago
- Status changed from In Progress to Under Review
Patch set 3 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at http://review.typo3.org/32610
Updated by Gerrit Code Review almost 10 years ago
Patch set 4 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at http://review.typo3.org/32610
Updated by Gerrit Code Review almost 10 years ago
Patch set 5 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at http://review.typo3.org/32610
Updated by Gerrit Code Review almost 10 years ago
Patch set 6 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at http://review.typo3.org/32610
Updated by Helmut Hummel over 9 years ago
- Status changed from Under Review to Closed
- Assignee deleted (
Sascha Egerer)
Resolved as duplicate
Updated by Anja Leichsenring almost 9 years ago
- Sprint Focus deleted (
On Location Sprint)