From e9fe735920169bfab9cef1b4b7b8aacc610071a3 Mon Sep 17 00:00:00 2001 From: Manuel Cillero Date: Tue, 8 May 2018 12:55:40 +0200 Subject: [PATCH] Applied D6LTS critical patch SA-CORE-2018-004 --- modules/filefield/filefield.module | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/filefield/filefield.module b/modules/filefield/filefield.module index 9045c10..fad1746 100644 --- a/modules/filefield/filefield.module +++ b/modules/filefield/filefield.module @@ -590,7 +590,7 @@ function filefield_js($type_name, $field_name, $delta) { // JSON output. $GLOBALS['devel_shutdown'] = FALSE; - if (empty($field) || empty($_POST['form_build_id'])) { + if (empty($field) || $field['type'] != 'filefield' || !is_numeric($delta) || empty($_POST['form_build_id'])) { // Invalid request. drupal_set_message(t('An unrecoverable error occurred. The uploaded file likely exceeded the maximum file size (@size) that this server supports.', array('@size' => format_size(file_upload_max_size()))), 'error'); print drupal_to_js(array('data' => theme('status_messages')));