Impact
The is_image and mime_in upload rules can accept filenames with trailing dots that conceal a PHP extension. These rules and ext_in can also accept a PHP extension before the final image extension.
Applications may be vulnerable to remote code execution if they preserve such client-supplied filenames in a web-accessible directory whose server configuration executes them as PHP.
Patches
Upgrade to v4.7.5 or later.
Workarounds
- Store uploads outside the public web root, preferably with
$file->store().
- If uploads must be public, disable script execution in the upload directory and use
$file->move($path, $file->getRandomName()).
- If client filenames must be preserved, reject trailing dots and PHP extensions in any dot-separated part of the filename.
References
Impact
The
is_imageandmime_inupload rules can accept filenames with trailing dots that conceal a PHP extension. These rules andext_incan also accept a PHP extension before the final image extension.Applications may be vulnerable to remote code execution if they preserve such client-supplied filenames in a web-accessible directory whose server configuration executes them as PHP.
Patches
Upgrade to v4.7.5 or later.
Workarounds
$file->store().$file->move($path, $file->getRandomName()).References
is_imageandmime_inrulesext_inrule