impresspages / ImpressPages

ImpressPages is php framework with admin panel. Build functional website in one hour.
http://www.impresspages.org
Other
501 stars 179 forks source link

Unable to upload images with TinyMCE Complete Editor and modsecurity WAF #825

Closed pauser0000001 closed 7 years ago

pauser0000001 commented 7 years ago

Hello,

First, thanks for such a nice CMS.

I have a problem with TinyMCE Complete, because I can't upload images with the responsive filemanager, because the server has a WAF and one of its rules forbids the upload of files with ../ in it, and this is what responsive filemanager does. I have no problem with the other filemanager in the image widget.

Example of a file upload:

-----------------------------10126241831743688427342282539 Content-Disposition: form-data; name="path"

../../../file/manual/ -----------------------------10126241831743688427342282539 Content-Disposition: form-data; name="path_thumb"

../../../file/manual-thumbs/ -----------------------------10126241831743688427342282539 Content-Disposition: form-data; name="file"; filename="example.jpg" Content-Type: image/jpeg

Best Regards.

maskas commented 7 years ago

This is a third party plugin https://market.impresspages.org/plugins/TinyMceComplete