Magento security patch and broken WYSIWYG file browser

Magento

Unfortunately, the security patch released by Magento last week has a small side effect. If the media directory is included via a symlink, which is quite common in larger shop installations, the file browser in the WYSIWYG editor no longer works.

The problem can easily be reproduced with the following command:

mv media media_shared && ln -s media_shared media

Since we at my employer netz98 promptly updated all customer installations with the patch because of the security vulnerability, this naturally came to light quickly.

The problem lies in comparing directories once with and once without the PHP function realpath. We created a small quick fix for this, which I do not want to keep from the public:

class Mage_Cms_Helper_Wysiwyg_Images extends Mage_Core_Helper_Abstract
{
   //....

   /**
    * Decode HTML element id
    *
    * @param string $id
    * @return string
    */
    public function convertIdToPath($id)
    {
        /*$path = $this->idDecode($id);
        if (!strstr($path, $this->getStorageRoot())) {
            $path = $this->getStorageRoot() . $path;
        }
        return $path;*/
        /**
        * CORE PATCH BY netz98 new media GmbH
        *
        * Problems with Symlinks after security patch by Magento
        */
        // BEGIN OF PATCH
        $path = $this->idDecode($id);
        if (!strstr($path, realpath($this->getStorageRoot()))) {
            $path = realpath($this->getStorageRoot()) . $path;
        }
        // END OF PATCH
        return $path;
    }

    //....
}

Procedure:

  • Copy the original file from the core code pool to local.
  • Replace the convertIdToPath method with the one above.