From 61a23da1925119454d8477e9cf884b6cba93364c Mon Sep 17 00:00:00 2001 From: Ajaysen R <40132420+ajaysenr@users.noreply.github.com> Date: Sun, 13 Mar 2022 12:01:44 +0000 Subject: [PATCH] Update AttachmentModel.class.php --- server/Application/Api/Model/AttachmentModel.class.php | 1 + 1 file changed, 1 insertion(+) diff --git a/server/Application/Api/Model/AttachmentModel.class.php b/server/Application/Api/Model/AttachmentModel.class.php index 8a17a6c3c..3f33fde76 100644 --- a/server/Application/Api/Model/AttachmentModel.class.php +++ b/server/Application/Api/Model/AttachmentModel.class.php @@ -305,6 +305,7 @@ public function isDangerFilename($filename){ || $isDangerStr($filename , ".xml") || $isDangerStr($filename , ".xxhtml") || $isDangerStr($filename , ".asp") + || $isDangerStr($filename , ".xsl") ) { return true; }