Search code examples
securitycodeigniterdirectorytraversalsanitize

CodeIgniter - Directory Traversal - sanitize_filename()


If I use the CodeIgniter File Upload Class and rename the image being uploaded using:

$config['file_name']

do I still have to use

$this->security->sanitize_filename()

on the image being uploaded by user?


Solution

  • just set $config['encrypt_name']; will automatically rename users uploaded file or image for more information check user guide of File uploading library

    File Upload Library