From a32dac2e1936c1473fa70e6ef5143ee11a3dfdfe Mon Sep 17 00:00:00 2001 From: Chris Sangwin Date: Tue, 21 Jan 2025 10:10:06 +0000 Subject: [PATCH] Fix typo. --- api/public/cors.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/api/public/cors.php b/api/public/cors.php index 1cd68d2cfb..55fd2d0d6d 100644 --- a/api/public/cors.php +++ b/api/public/cors.php @@ -27,7 +27,7 @@ $is_question = false; } -if (str_pos($scriptname, '..') !== false +if (strpos($scriptname, '..') !== false || strpos($scriptname, '/') !== false || strpos($scriptname, '\\') !== false) { die("No such script here.");