plegall / Piwigo-community

11 stars 23 forks source link

Upload protections not working properly - Piwigo 12.2.0 #71

Open sinkillerj opened 2 years ago

sinkillerj commented 2 years ago

It appears that "if (isset($_GET['processed']))" is not working properly in "add_photos.php".

As no code in this block is being called, a user is able to perform actions such as editing the form to upload to another gallery, or add more photos to the upload list than they are allowed thus bypassing the limit.