From 8781a086a0d72bf06c70b1bac39a37cb08448c4f Mon Sep 17 00:00:00 2001 From: Pavan Kumar Reddy Balireddy Date: Mon, 28 Sep 2026 08:43:46 +0530 Subject: [PATCH] RDKB-67104 : Safely handles missing/empty POST fields --- .../Styles/xb3/jst/actionHandler/ajaxSet_at_downloading.jst | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/source/Styles/xb3/jst/actionHandler/ajaxSet_at_downloading.jst b/source/Styles/xb3/jst/actionHandler/ajaxSet_at_downloading.jst index a6e20c2..9dda928 100644 --- a/source/Styles/xb3/jst/actionHandler/ajaxSet_at_downloading.jst +++ b/source/Styles/xb3/jst/actionHandler/ajaxSet_at_downloading.jst @@ -26,11 +26,12 @@ if (!(isset($_SESSION["loginuser"]) || isset($_SESSION["password_change"]))) { echo( ''); exit(0); } -if (($_POST['FileName'] != "") && ($_POST['UserInputPassword'] != "")) { +$result = "Failure!"; +if (isset($_POST['FileName']) && isset($_POST['UserInputPassword'])) { $Filename = $_POST['FileName']; $Password = $_POST['UserInputPassword']; $output = []; //Fail by default - if(preg_match('/^[a-zA-Z0-9]{8,20}$/', $Password)==1 && preg_match('/^.*[a-z].*$/', $Password)==1 && preg_match('/^.*[A-Z].*$/', $Password)==1 && preg_match('/^.*[0-9].*$/', $Password)==1 && (preg_match('/^.*[a-z].*$/', $Filename)==1 || preg_match('/^.*[A-Z].*$/', $Filename)==1 || preg_match('/^.*[0-9].*$/', $Filename)==1)) { + if(preg_match('/^[a-zA-Z0-9]{8,20}$/', $Password)==1 && preg_match('/^.*[a-z].*$/', $Password)==1 && preg_match('/^.*[A-Z].*$/', $Password)==1 && preg_match('/^.*[0-9].*$/', $Password)==1 && preg_match('/^[a-zA-Z0-9]{3,63}$/', $Filename)==1) { $command = "/usr/bin/save_restore_config save"+" "+escapeshellarg($Filename)+" "+escapeshellarg($Password); $output = exec($command); } @@ -40,7 +41,6 @@ if (($_POST['FileName'] != "") && ($_POST['UserInputPassword'] != "")) { $saveStatus = Number(trim($output[$output.length -1])); } if ($saveStatus != 0) { - $result = "Failure!"; LogStr(" : webui_event:save_restore_config_failed"); } else { $result = "Success!";