Skip to content

Commit 8f6587c

Browse files
committed
Merge branch '4.x-advisories' of https://github.com/pixelandtonic/cms-internal into 5.x-advisories
# Conflicts: # CHANGELOG.md
2 parents fecd8a2 + c13d539 commit 8f6587c

2 files changed

Lines changed: 10 additions & 3 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22

33
## Unreleased
44

5+
<<<<<<< HEAD
56
- Fixed a bug where entries weren’t redirecting back to their section’s page’s URL by default.
67
- Fixed a bug where the `resourceBasePath` and `resourceBaseUrl` config settings weren’t being respected for console requests. ([#18685](https://github.com/craftcms/cms/issues/18685))
78
- Fixed a bug where eager-loadable GraphQL fields could be populated with the wrong field’s results, if they followed a fragment with a `*Interface` type condition. ([#18708](https://github.com/craftcms/cms/issues/18708))
@@ -11,7 +12,7 @@
1112
- Fixed a bug where it wasn’t always possible to sign into a user account that had the same email address as an inactive user. ([#18723](https://github.com/craftcms/cms/issues/18723))
1213
- Fixed a bug where relational fields’ element query results weren’t always limited to the selected relations if the `id` param was overridden. ([#15570](https://github.com/craftcms/cms/issues/15570))
1314
- Fixed an error that could occur when executing a queue job. ([#18739](https://github.com/craftcms/cms/issues/18739))
14-
- Fixed [high-severity](https://github.com/craftcms/cms/security/policy#severity--remediation) authorization bypass vulnerabilities. (GHSA-x5m4-g2cq-52pq, GHSA-3w32-23wj-rxg3)
15+
- Fixed [high-severity](https://github.com/craftcms/cms/security/policy#severity--remediation) authorization bypass vulnerabilities. (GHSA-x5m4-g2cq-52pq, GHSA-3w32-23wj-rxg3, GHSA-qh45-9g5p-m2v4)
1516
- Fixed [moderate-severity](https://github.com/craftcms/cms/security/policy#severity--remediation) permission escalation vulnerabilities. (GHSA-qq2c-2q8j-jh27, GHSA-43cq-c2gq-pfpw)
1617

1718
## 5.9.20 - 2026-04-14

‎src/controllers/AssetsController.php‎

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -430,8 +430,14 @@ public function actionReplaceFile(): Response
430430
throw new NotFoundHttpException('Asset not found.');
431431
}
432432

433-
$this->requireVolumePermissionByAsset('replaceFiles', $assetToReplace ?: $sourceAsset);
434-
$this->requirePeerVolumePermissionByAsset('replacePeerFiles', $assetToReplace ?: $sourceAsset);
433+
if ($assetToReplace) {
434+
$this->requireVolumePermissionByAsset('replaceFiles', $assetToReplace);
435+
$this->requirePeerVolumePermissionByAsset('replacePeerFiles', $assetToReplace);
436+
}
437+
if ($sourceAsset) {
438+
$this->requireVolumePermissionByAsset('replaceFiles', $sourceAsset);
439+
$this->requirePeerVolumePermissionByAsset('replacePeerFiles', $sourceAsset);
440+
}
435441

436442
// Handle the Element Action
437443
if ($assetToReplace !== null && $uploadedFile) {

0 commit comments

Comments
 (0)