[Tickets #14857] Re: Multiple XSS security vulnerabilities

[email protected]
Newsgroups gmane.comp.horde.bugs
Message-ID <[email protected]>
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: https://bugs.horde.org/ticket/14857
------------------------------------------------------------------------------
  Ticket             | 14857
  Updated By         | Git Commit <[email protected]>
  Summary            | Multiple XSS security vulnerabilities
  Queue              | Horde Groupware
  Version            | 5.2.22
  Type               | Bug
  State              | Assigned
  Priority           | 3. High
  Milestone          |
  Patch              |
  Owners             | Michael Rubinsky
------------------------------------------------------------------------------


Git Commit <[email protected]> (2018-09-25 16:11) wrote:

Changes have been made in Git (master):

commit da2342594b749f1f88747cbb11ecfdc188f64a85
Author: Michael J Rubinsky <[email protected]>
Date:   Tue, 25 Sep 2018 12:10:39 -0400

Bug: 14857

Escape user supplied $color value and prevent XSS vuln.

  M lib/Horde/Core/Ui/VarRenderer/Html.php

https://github.com/horde/Core/commit/da2342594b749f1f88747cbb11ecfdc188f64a85



-- 
bugs mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.