-
Notifications
You must be signed in to change notification settings - Fork 290
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Install subdirectory not disabled and publicly reachable #507
Comments
The install tool autolock feature was removed in release 0.4.0 |
Does it mean that anybody can access the install tool and mess with the SQLite file path? |
That seems pretty problematic as the SQLite file path is arbitrary PHP code that is executed. |
Deleting |
This is indeed bad news. I was under the impression that the installation will not run, if baikal is already fully configured/installed. |
I'm now disabling the installer altogether if baikal was configured. Sorry I missed this :/ |
Upgrading now: thank you for the quick fix! Edit: Upgrade done, it's working well. Thank you again. |
Upgraded from 0.3.5 to 0.4.1, upgrade went well, but the /admin/install path seems not to be disabled.
I can still access it. Configuration is NGinx and PHP-FPM.
The text was updated successfully, but these errors were encountered: