diff --git a/data/CRMEntity.php b/data/CRMEntity.php index 0c4dd4800c560ae852dae41d281d082684758713..dc367763c29fcc503134f747be144af97133a4eb 100644 --- a/data/CRMEntity.php +++ b/data/CRMEntity.php @@ -193,7 +193,7 @@ class CRMEntity { if ($module == 'Contacts' || $module == 'Products') { $save_file = validateImageFile($file_details); } - + $binFile = sanitizeUploadFileName($file_name, $upload_badext); $current_id = $adb->getUniqueID("vtiger_crmentity"); diff --git a/include/utils/VtlibUtils.php b/include/utils/VtlibUtils.php index 4aec8b490f83f6374049984d33be24378cbee515..51b35ba0e2341e08956629c2ba7d40b93f9fb4ba 100644 --- a/include/utils/VtlibUtils.php +++ b/include/utils/VtlibUtils.php @@ -826,4 +826,5 @@ function vtlib_addSettingsLink($linkName, $linkURL, $blockName = false) { } return $success; } + ?> \ No newline at end of file diff --git a/modules/Settings/Vtiger/actions/CompanyDetailsSave.php b/modules/Settings/Vtiger/actions/CompanyDetailsSave.php index d23d795fb3a890a2770856a2ea1b2a8b587d2250..6c644da599ccb9c32ae0460ff4322094b50e6fd4 100644 --- a/modules/Settings/Vtiger/actions/CompanyDetailsSave.php +++ b/modules/Settings/Vtiger/actions/CompanyDetailsSave.php @@ -49,13 +49,6 @@ class Settings_Vtiger_CompanyDetailsSave_Action extends Settings_Vtiger_Basic_Ac $saveLogo = false; } - //mime type check - $mimeType = mime_content_type($logoDetails['tmp_name']); - $mimeTypeContents = explode('/', $mimeType); - if (!$logoDetails['size'] || $mimeTypeContents[0] != 'image' || !in_array($mimeTypeContents[1], Settings_Vtiger_CompanyDetails_Model::$logoSupportedFormats)) { - $saveLogo = false; - } - // Check for php code injection $imageContents = file_get_contents($logoDetails["tmp_name"]); if (preg_match('/(<\?php?(.*?))/i', $imageContents) == 1) { @@ -100,4 +93,4 @@ class Settings_Vtiger_CompanyDetailsSave_Action extends Settings_Vtiger_Basic_Ac public function validateRequest(Vtiger_Request $request) { $request->validateWriteAccess(); } -} +} \ No newline at end of file