diff --git a/tinyfilemanager.php b/tinyfilemanager.php index 9a41e334..5b57b7bc 100644 --- a/tinyfilemanager.php +++ b/tinyfilemanager.php @@ -1065,6 +1065,15 @@ function get_file_path () { } $files = $_POST['file']; + $sanitized_files = array(); + + // clean path + foreach($files as $file){ + array_push($sanitized_files, fm_clean_path($file)); + } + + $files = $sanitized_files; + if (!empty($files)) { chdir($path);