[!!!][SECURITY] Add CSRF Protection for tce_file.php
Add a token check in tce_file.php and token generation everywhere forms for or links to tce_file.php are created. Additionaly make sure, an instance of ExtendedFileUtility is created in FileController on initialization to prevent a fatal "Call to a member function on a non-object" error in FileController::finish. Releases: 6.2 Resolves: #55515 Change-Id: Ifd585661ac2cac6c88eaca5ad63b447d27e35395 Reviewed-on: https://review.typo3.org/27691 Reviewed-by: Helmut Hummel Tested-by: Helmut Hummel
Showing
- typo3/sysext/backend/Classes/ClickMenu/ClickMenu.php 2 additions, 2 deletionstypo3/sysext/backend/Classes/ClickMenu/ClickMenu.php
- typo3/sysext/backend/Classes/Controller/File/CreateFolderController.php 2 additions, 0 deletions...ackend/Classes/Controller/File/CreateFolderController.php
- typo3/sysext/backend/Classes/Controller/File/EditFileController.php 1 addition, 0 deletions...xt/backend/Classes/Controller/File/EditFileController.php
- typo3/sysext/backend/Classes/Controller/File/FileController.php 1 addition, 1 deletion...sysext/backend/Classes/Controller/File/FileController.php
- typo3/sysext/backend/Classes/Controller/File/FileUploadController.php 1 addition, 0 deletions.../backend/Classes/Controller/File/FileUploadController.php
- typo3/sysext/backend/Classes/Controller/File/RenameFileController.php 1 addition, 0 deletions.../backend/Classes/Controller/File/RenameFileController.php
- typo3/sysext/filelist/Classes/FileList.php 1 addition, 1 deletiontypo3/sysext/filelist/Classes/FileList.php
- typo3/sysext/recordlist/Classes/Browser/ElementBrowser.php 2 additions, 0 deletionstypo3/sysext/recordlist/Classes/Browser/ElementBrowser.php
- typo3/tce_file.php 7 additions, 2 deletionstypo3/tce_file.php
Please register or sign in to comment