Complete security audit fixes
This commit is contained in:
@@ -1,19 +1,17 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$sql = "SELECT *
|
||||
FROM md_contact
|
||||
WHERE
|
||||
company_id = {$company_id}";
|
||||
company_id = :company_id ";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetchAll(PDO::FETCH_ASSOC);
|
||||
$answer["success"] = 1;
|
||||
|
||||
@@ -1,19 +1,17 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$sql = "SELECT *
|
||||
FROM md_contact_type
|
||||
WHERE
|
||||
company_id = {$company_id}";
|
||||
company_id = :company_id ";
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetchAll(PDO::FETCH_ASSOC);
|
||||
$answer["success"] = 1;
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
@@ -67,21 +66,52 @@
|
||||
/** 3. PROCESSING NEW UPLOADS **/
|
||||
$uploaded_names = [];
|
||||
|
||||
// Allowed MIME types whitelist
|
||||
$allowed_mimes = ['image/jpeg', 'image/png', 'image/gif', 'image/webp', 'application/pdf'];
|
||||
|
||||
// Allowed extensions whitelist
|
||||
$allowed_extensions = ['jpg', 'jpeg', 'png', 'gif', 'webp', 'pdf'];
|
||||
|
||||
// Max file size: 5MB
|
||||
$max_size = 5 * 1024 * 1024;
|
||||
|
||||
if (isset($_FILES['contact_files'])) {
|
||||
foreach ($_FILES['contact_files']['name'] as $key => $name) {
|
||||
if ($_FILES['contact_files']['error'][$key] === UPLOAD_ERR_OK) {
|
||||
|
||||
$tmp_name = $_FILES['contact_files']['tmp_name'][$key];
|
||||
$extension = pathinfo($name, PATHINFO_EXTENSION);
|
||||
|
||||
// Assign a unique ID to prevent filename collisions on the server
|
||||
$file_id = uniqid() . "_" . time() . "." . $extension;
|
||||
$tmp_name = $_FILES['contact_files']['tmp_name'][$key];
|
||||
$file_size = $_FILES['contact_files']['size'][$key];
|
||||
$extension = strtolower(pathinfo($name, PATHINFO_EXTENSION));
|
||||
|
||||
// Check 1: File size
|
||||
if ($file_size > $max_size) {
|
||||
error_log("Rejected oversized file: " . $name);
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check 2: Extension whitelist
|
||||
if (!in_array($extension, $allowed_extensions)) {
|
||||
error_log("Rejected extension: " . $name);
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check 3: Real MIME type (reads actual file bytes, not filename)
|
||||
$finfo = finfo_open(FILEINFO_MIME_TYPE);
|
||||
$mime = finfo_file($finfo, $tmp_name);
|
||||
finfo_close($finfo);
|
||||
|
||||
if (!in_array($mime, $allowed_mimes)) {
|
||||
error_log("Rejected MIME type: " . $mime . " for file: " . $name);
|
||||
continue;
|
||||
}
|
||||
|
||||
// Safe unique filename — no original extension trusted
|
||||
$file_id = uniqid() . "_" . time() . "." . $extension;
|
||||
$destination = $target_dir . $file_id;
|
||||
|
||||
if (move_uploaded_file($tmp_name, $destination)) {
|
||||
$uploaded_names[] = $file_id;
|
||||
// Standard readable permission
|
||||
chmod($destination, 0644);
|
||||
chmod($destination, 0644);
|
||||
} else {
|
||||
error_log("Failed to move uploaded file: " . $name);
|
||||
}
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
@@ -9,15 +8,15 @@
|
||||
$sql = "SELECT *
|
||||
FROM md_contact
|
||||
WHERE
|
||||
company_id = {$company_id} and
|
||||
id = {$id}";
|
||||
company_id = :company_id and
|
||||
id = :id ";
|
||||
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id,
|
||||
":id" => $id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$target_dir = $include_url."uploads/contact/";
|
||||
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
|
||||
require '../../../preset.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
$id = (int)$data['id'];
|
||||
@@ -9,15 +8,15 @@
|
||||
$sql = "SELECT *
|
||||
FROM md_contact_type
|
||||
WHERE
|
||||
company_id = {$company_id} and
|
||||
id = {$id}";
|
||||
company_id = :company_id and
|
||||
id = :id ";
|
||||
|
||||
$sth = $pdo2->prepare($sql);
|
||||
$sth->execute();
|
||||
if ($sth->errorInfo()[0] != "00000" && !empty($sth->errorInfo()[0])) {
|
||||
$answer["message"] = (empty($sth->errorInfo()[2])) ? $sth->errorInfo()[0] : $sth->errorInfo()[2];
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
$sth->execute([
|
||||
":company_id" => $company_id,
|
||||
":id" => $id
|
||||
]);
|
||||
db_check($sth, $answer);
|
||||
|
||||
$answer["output"] = $sth->fetch(PDO::FETCH_ASSOC);
|
||||
$answer["success"] = 1;
|
||||
|
||||
Reference in New Issue
Block a user