Block access to all php and phar files that are uploaded into the media folder

This commit is contained in:
Jan Böhmer 2026-06-07 20:40:15 +02:00
parent c2ec0ee12b
commit 6e5d1c967f
5 changed files with 29 additions and 1 deletions

View file

@ -51,5 +51,9 @@
# Disable Topics tracking if not enabled explicitly: https://github.com/jkarlin/topics
header ?Permissions-Policy "browsing-topics=()"
# Prevent PHP execution in the media upload directory
@php_in_media path_regexp (?i)^/media/.*\.(php[3-8]?|phar|phtml|pht|phps)$
respond @php_in_media 403
php_server
}