--- magento2-2.4.6-p8/Download.php
+++ magento2-2.4.6-p9/Download.php
@@ -81,13 +81,11 @@
return $resultRedirect;
}
- // phpcs:ignore Magento2.Functions.DiscouragedFunction
- $fileName = basename($fileName);
-
- $exportDirectory = $this->filesystem->getDirectoryRead(...);
+ $exportDirectory = $this->filesystem->getDirectoryWrite(...);
try {
- $fileExist = $exportDirectory->isExist('export/' . $fileName);
+ $fileName = $exportDirectory->getDriver()->getRealPathSafety(...);
+ $fileExist = $exportDirectory->isExist('export' . $fileName);
} catch (Throwable $e) {
$fileExist = false;
}
Identified CVE-2024-47048: Rocket.Chat 6.12.0 and earlier allows stored XSS in the description and release notes of the marketplace and private apps.
Folder Analysis
Comparing versions: Magento 2.4.6-p8 → 2.4.6-p9
Analyzes security patches between local directory versions