diff --git a/umbraco/presentation/umbraco/developer/Macros/assemblyBrowser.aspx.cs b/umbraco/presentation/umbraco/developer/Macros/assemblyBrowser.aspx.cs index 7e1fd772c6..a89d6eee49 100644 --- a/umbraco/presentation/umbraco/developer/Macros/assemblyBrowser.aspx.cs +++ b/umbraco/presentation/umbraco/developer/Macros/assemblyBrowser.aspx.cs @@ -41,6 +41,9 @@ namespace umbraco.developer isUserControl = true; string fileName = Request.QueryString["fileName"]; + IOHelper.ValidateEditPath(fileName, SystemDirectories.Usercontrols); + + if (System.IO.File.Exists(IOHelper.MapPath("~/" + fileName))) { UserControl oControl = (UserControl)LoadControl(@"~/" + fileName);