Minor patch

This commit is contained in:
Miroslav Štampar 2026-06-04 21:34:11 +02:00
parent b67ea8f294
commit 3e8a69cfbe
3 changed files with 4 additions and 4 deletions

View file

@ -660,7 +660,7 @@ def download(taskid, target, filename):
path = os.path.abspath(os.path.join(paths.SQLMAP_OUTPUT_PATH, target, filename))
# Prevent file path traversal
if not path.startswith(paths.SQLMAP_OUTPUT_PATH):
if not path.startswith(os.path.join(paths.SQLMAP_OUTPUT_PATH, "")):
logger.warning("[%s] Forbidden path (%s)" % (taskid, target))
return jsonize({"success": False, "message": "Forbidden path"})