Files
Bubberstation/code/modules/admin/verbs
Watermelon914 dc64f47f98 Fixed a vulnerability introduced by the Request Music PR (#75691)
Admins can proccall the web_sound proc, completely bypassing the
shell_url_scrub done in other procs. Additionally, admins could just
directly modify the request URL stored in the request manager so that
it, again, bypasses the shell_url_scrub.

This PR just moves the shell scrubbing directly inside the proc, right
before the world.shelleo call, so that admins can't get around it with a
proccall.
2023-05-27 17:30:16 +00:00
..