Watermelon914
dc64f47f98
Fixed a vulnerability introduced by the Request Music PR ( #75691 )
...
Admins can proccall the web_sound proc, completely bypassing the
shell_url_scrub done in other procs. Additionally, admins could just
directly modify the request URL stored in the request manager so that
it, again, bypasses the shell_url_scrub.
This PR just moves the shell scrubbing directly inside the proc, right
before the world.shelleo call, so that admins can't get around it with a
proccall.
2023-05-27 17:30:16 +00:00
..
2023-04-05 15:36:26 -07:00
2023-03-29 10:17:03 -07:00
2023-03-28 12:12:48 +01:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-02-05 11:44:38 +13:00
2023-02-05 11:44:38 +13:00
2023-04-25 20:20:02 -06:00
2023-02-05 11:44:38 +13:00
2023-02-05 11:44:38 +13:00
2023-02-05 11:44:38 +13:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-05-22 13:29:20 +00:00
2023-04-25 20:20:02 -06:00
2023-02-05 11:44:38 +13:00
2023-02-05 11:44:38 +13:00
2023-02-05 11:44:38 +13:00
2023-04-25 20:20:02 -06:00
2023-02-05 11:44:38 +13:00
2023-02-05 11:44:38 +13:00
2023-05-08 19:28:18 +00:00
2023-04-25 20:20:02 -06:00
2023-02-05 11:44:38 +13:00
2023-04-25 20:20:02 -06:00
2023-03-14 18:33:35 -06:00
2023-02-05 11:44:38 +13:00
2023-04-25 20:20:02 -06:00
2023-02-05 11:44:38 +13:00
2023-04-25 20:20:02 -06:00
2023-02-05 11:44:38 +13:00
2023-05-27 17:30:16 +00:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-05-27 17:30:16 +00:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00
2023-04-25 20:20:02 -06:00