jet-admin / jet-bridge

Audit required: External control of file name or path PTC-W6004
Security
Minor
6 months ago2 years old
External variable 'path' used in file path
110        return os.path.getsize(absolute_path)
111
112    def media_open(self, path, mode='rb'):
113        return open(path, mode)114
115    def media_save(self, path, content):
116        absolute_path = os.path.join(settings.MEDIA_ROOT, path)