OrchardCMS / Orchard

Orchard is a free, open source, community-focused Content Management System built on the ASP.NET MVC platform.
https://orchardproject.net
BSD 3-Clause "New" or "Revised" License
2.38k stars 1.12k forks source link

Media Settings does not restrict file extensions #1885

Open orchardbot opened 13 years ago

orchardbot commented 13 years ago

JDAS created: https://orchard.codeplex.com/workitem/18058

After I restricted what type of files are allowed to be upload under media section, the upload mechanism allow me to upload any type of files, i.e. swf, css, etc.

orchardbot commented 12 years ago

@agriffard commented:

Still not restricting file type on uploading a media in a folder. Repro :

burninatorsec commented 3 years ago

For Orchard CMS v.1.8.1.0, is the intention for this file type to restrict any file type to be written to the media folder? If so, I've noticed this can be bypassed depending on which file upload page is used.