Assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured.
Impact
- Affects front-end forms with
assets
fields.
- Affects other places where assets can be uploaded, although users would need upload permissions anyway.
- Files can be uploaded so they would be located on the server in a different location, and potentially override existing files.
- Traversal outside an asset container was not possible.
Patches
This has been fixed in 5.17.0.
References
Assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured.
Impact
assets
fields.Patches
This has been fixed in 5.17.0.
References