Skip to content

Fix - Enforce Album permissions, allowlist, sanitization on media edit - #2373

Merged
Intenzi merged 3 commits into
developfrom
fix/media-edit-security-fixes
Sep 30, 2026
Merged

Intenzi merged 3 commits into
developfrom
fix/media-edit-security-fixes

Conversation

@Intenzi

@Intenzi Intenzi commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Summary

Addresses authorization and mass database assignment vulnerabilities in media edit requests.

Changes

  1. Album Permission Check: Added rtmedia_current_user_can_add_to_album() verification in RTMediaTemplate::save_single_edit() before allowing media to be moved to a destination album.

  2. Strict Allowlist Sanitization: Updated rtmedia_sanitize_object() to enforce a strict allowlist using the $exceptions parameter, preventing arbitrary database columns (e.g., media_author, views, likes) from being modified.

  3. Privacy Level Validation: Validated privacy key input via rtmedia_sanitize_privacy_level() to ensure only allowed privacy integers are stored.

@Intenzi Intenzi self-assigned this Sep 29, 2026
@Intenzi Intenzi added the bug label Sep 29, 2026
@rtBot

rtBot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Unable to PHPCS or SVG scan one or more files due to error running PHPCS/SVG scanner:

  • app/main/controllers/template/RTMediaTemplate.php
  • app/main/controllers/template/rtmedia-functions.php
  • app/main/controllers/upload/RTMediaUploadEndpoint.php

The error may be temporary. If the error persists, please contact a human (commit-ID: be9386a).

@NoumaanAhamed
NoumaanAhamed requested a balanced review from Copilot September 29, 2026 18:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Intenzi
Intenzi merged commit 1be2b05 into develop Sep 30, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants