Files
Bubberstation/code/modules
Watermelon914 dc64f47f98 Fixed a vulnerability introduced by the Request Music PR (#75691)
Admins can proccall the web_sound proc, completely bypassing the
shell_url_scrub done in other procs. Additionally, admins could just
directly modify the request URL stored in the request manager so that
it, again, bypasses the shell_url_scrub.

This PR just moves the shell scrubbing directly inside the proc, right
before the world.shelleo call, so that admins can't get around it with a
proccall.
2023-05-27 17:30:16 +00:00
..
2023-05-15 04:27:43 +00:00
2023-05-21 11:32:07 -07:00
2023-05-12 10:54:06 +00:00
2023-05-23 17:07:55 -06:00
2023-05-15 04:27:43 +00:00
2023-05-12 20:43:00 -06:00
2023-05-26 01:07:03 +00:00
2023-05-16 20:19:04 -06:00
2023-05-15 04:27:43 +00:00