Belikhun/themis-web-interface

get avatar API bug

Closed this issue · 1 comments

Describe the bug
We can use /api/avt/get to read content of other file

To Reproduce
Steps to reproduce the behavior:

  1. Go to api/avt/get?u=get or api/avt/get?u=change
  2. A part of get.php or change.php showed up

Expected behavior
Should return default avatar

Screenshots
image

Additional context

Much empty

Fixed in commit b311eb3