Fixed
Details
Assignee
Pothys - MitrahSoftPothys - MitrahSoftReporter
Pothys - MitrahSoftPothys - MitrahSoftPriority
NewLabels
Fix versions
New Issue warning screen
Before you create a new Issue, please post to the mailing list first https://dev.lucee.org
Once the issue has been verified, one of the Lucee team will ask you to file an issue
Affects versions
Details
Details
Assignee
Pothys - MitrahSoft
Pothys - MitrahSoftReporter
Pothys - MitrahSoft
Pothys - MitrahSoftPriority
Labels
Fix versions
New Issue warning screen
Before you create a new Issue, please post to the mailing list first https://dev.lucee.org
Once the issue has been verified, one of the Lucee team will ask you to file an issue
Affects versions
Created 14 October 2022 at 09:34
Updated 18 June 2023 at 16:42
Resolved 26 April 2023 at 14:44
this.blockedextforfileupload defined in the Appplication.cfc doesn't block the file upload (via cfile action=upload, fileUpload(), fileUploadAll())
Example:
this.blockedextforfileupload = "cfm,pdf";
in the application.cfc didn't block the pdf/cfm file uploadsThe regression starts from 5.3.8.107-SNAPSHOT onwards. The ticket https://luceeserver.atlassian.net/browse/LDEV-3018 fix causes to this issue.
regression commit: https://github.com/lucee/Lucee/commit/e233efd4e0a56b3cd59ea68a46187fcdd69ca89e