From ba45d19e1d77a7eea866dab30eff5da552694891 Mon Sep 17 00:00:00 2001 From: star7th Date: Mon, 14 Mar 2022 10:52:48 +0800 Subject: [PATCH] bug --- server/Application/Api/Model/AttachmentModel.class.php | 2 ++ 1 file changed, 2 insertions(+) diff --git a/server/Application/Api/Model/AttachmentModel.class.php b/server/Application/Api/Model/AttachmentModel.class.php index 3a41ecd99..b518b9b57 100644 --- a/server/Application/Api/Model/AttachmentModel.class.php +++ b/server/Application/Api/Model/AttachmentModel.class.php @@ -309,6 +309,8 @@ public function isDangerFilename($filename){ || $isDangerStr($filename , ".aspx") || $isDangerStr($filename , ".xsd") || $isDangerStr($filename , ".asa") + || $isDangerStr($filename , ".cshtml") + || $isDangerStr($filename , ".axd") ) { return true; }