From f9834936df435948c49d150ad9cebcaa67b6583d Mon Sep 17 00:00:00 2001 From: liugang Date: Mon, 8 Apr 2024 14:59:46 +0800 Subject: [PATCH] + helper: filter the sessionID paramter to fix directory traversal vulnerablity. --- framework/base/helper.class.php | 1 + 1 file changed, 1 insertion(+) diff --git a/framework/base/helper.class.php b/framework/base/helper.class.php index 5cb2e903a0..c85fb54397 100644 --- a/framework/base/helper.class.php +++ b/framework/base/helper.class.php @@ -743,6 +743,7 @@ class baseHelper */ public static function restartSession($sessionID = '') { + if(!preg_match('/^\w+$/', $sessionID)) $sessionID = ''; if(empty($sessionID)) $sessionID = sha1(mt_rand()); session_write_close();