From 32b72aff69f9b38eb7d4dd0e616c3c1221fa96f2 Mon Sep 17 00:00:00 2001 From: Angel Fernando Quiroz Campos Date: Mon, 30 Mar 2015 13:58:41 -0500 Subject: [PATCH] Fix load admin panels extra data - refs BT#9325 --- main/inc/ajax/admin.ajax.php | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/main/inc/ajax/admin.ajax.php b/main/inc/ajax/admin.ajax.php index 8b2b3c47e3..cdc3477faa 100755 --- a/main/inc/ajax/admin.ajax.php +++ b/main/inc/ajax/admin.ajax.php @@ -97,6 +97,10 @@ switch ($action) { $newUrlDir = api_get_path(SYS_PATH) . "home/admin/"; } + if (!file_exists($newUrlDir)) { + die; + } + if (!Security::check_abs_path("{$newUrlDir}{$blockName}_extra.html", $newUrlDir)) { die; }