DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.
Ticket URL: https://bugs.horde.org/ticket/14857
------------------------------------------------------------------------------
Ticket | 14857
Updated By | Git Commit <[email protected]>
Summary | Multiple XSS security vulnerabilities
Queue | Horde Groupware
Version | 5.2.22
Type | Bug
State | Assigned
Priority | 3. High
Milestone |
Patch |
Owners | Michael Rubinsky
------------------------------------------------------------------------------
Git Commit <[email protected]> (2018-09-25 16:11) wrote:
Changes have been made in Git (FRAMEWORK_5_2):
commit ecea6ea740419e19122a50579ba2903c1cb71d7a
Author: Michael J Rubinsky <[email protected]>
Date: Tue, 25 Sep 2018 12:11:51 -0400
Bug: 14857
Escape user supplied $color value and prevent XSS vuln.
M lib/Horde/Core/Ui/VarRenderer/Html.php
https://github.com/horde/Core/commit/ecea6ea740419e19122a50579ba2903c1cb71d7a
--
bugs mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.