mirror of
https://github.com/itflow-org/itflow
synced 2026-03-11 00:04:50 +00:00
Fix potential sql injection in delete_file if param add_location was also specified - post.php
This commit is contained in:
1
post.php
1
post.php
@@ -6804,6 +6804,7 @@ if(isset($_GET['delete_file'])){
|
|||||||
$sql_file = mysqli_query($mysqli,"SELECT * FROM files WHERE file_id = $file_id AND company_id = $session_company_id");
|
$sql_file = mysqli_query($mysqli,"SELECT * FROM files WHERE file_id = $file_id AND company_id = $session_company_id");
|
||||||
$row = mysqli_fetch_array($sql_file);
|
$row = mysqli_fetch_array($sql_file);
|
||||||
$client_id = $row['file_client_id'];
|
$client_id = $row['file_client_id'];
|
||||||
|
$file_name = $row['file_name'];
|
||||||
$file_reference_name = $row['file_reference_name'];
|
$file_reference_name = $row['file_reference_name'];
|
||||||
|
|
||||||
unlink("uploads/clients/$session_company_id/$client_id/$file_reference_name");
|
unlink("uploads/clients/$session_company_id/$client_id/$file_reference_name");
|
||||||
|
|||||||
Reference in New Issue
Block a user