Skip to content

Commit 4d4b3b4

Browse files
authored
Merge pull request #64 from solusio/bugfix-dshamanskaia-fix-cross-tenant-idor-in-custom-functions-SVM-4189
BUGFIX SVM-4189 Security bugfix
2 parents e793453 + 90225c0 commit 4d4b3b4

2 files changed

Lines changed: 8 additions & 6 deletions

File tree

‎modules/servers/solusvmpro/VERSION‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
4.2.1
1+
4.2.2

‎modules/servers/solusvmpro/solusvmpro.php‎

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1230,12 +1230,14 @@ function solusvmpro_UsageUpdate($params)
12301230
function solusvmpro_Custom_ChangeRescueMode( $params = '' ) {
12311231
global $_LANG;
12321232

1233-
$rescueAction = $_GET['rescueAction'];
1234-
$rescueValue = $_GET['rescueValue'];
1233+
$allowedActions = array( 'rescueenable', 'rescuedisable' );
1234+
$rescueAction = isset( $_GET['rescueAction'] ) ? $_GET['rescueAction'] : '';
12351235

1236-
if ( $rescueValue && $rescueAction) {
1237-
// The call string for the connection function
1238-
$callArray = array( 'vserverid' => $params['customfields']['vserverid'], $rescueAction => $rescueValue );
1236+
if ( in_array( $rescueAction, $allowedActions, true ) ) {
1237+
$callArray = array(
1238+
'vserverid' => $params['customfields']['vserverid'],
1239+
$rescueAction => 1,
1240+
);
12391241
$solusvm = new SolusVM( $params );
12401242

12411243
$solusvm->apiCall( 'vserver-rescue', $callArray );

0 commit comments

Comments
 (0)