mirror of
https://github.com/ether/etherpad-lite.git
synced 2026-05-05 04:06:37 +02:00
Fix directory traversal fixing RegExp
This commit is contained in:
parent
a1a1017bfe
commit
7557af3db7
@ -100,7 +100,7 @@ async.waterfall([
|
||||
{
|
||||
res.header("Server", serverName);
|
||||
var filePath = path.normalize(__dirname + "/.." +
|
||||
req.url.replace(/\./g, '').split("?")[0]);
|
||||
req.url.replace(/\.\./g, '').split("?")[0]);
|
||||
res.sendfile(filePath, { maxAge: exports.maxAge });
|
||||
});
|
||||
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user