mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #59189
[Bug 1874530] Re: extracting a zipped file's contents not working correctly
Also noticed a problem
4) a user guessing file IDs can initiate a zip file extraction for
another user, eg hitting the page artefact/file/extract.php?file= with a
valid ID for a zip file
luckily the files get extracted to the zip file owner and not the hacker
but we need to fix that up as well as they can see a list of filenames
in the zip file
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask on #mahara-dev or mahara.org forum before editing or unsubscribing it!
https://bugs.launchpad.net/bugs/1874530
Title:
extracting a zipped file's contents not working correctly
Status in Mahara:
In Progress
Bug description:
This page needs some fixing up, the current problems are:
1) The process bar is in the old css style and should be using the new
colours and not have a scroll bar in it
2) The general layout of the page could use some tidying up as well
3) The extraction of files looks to work but there is no redirect back
to files page (either automatically or via a button)
To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1874530/+subscriptions
References