[Tickets #14857] Re: Multiple XSS security vulnerabilities
noreply at bugs.horde.org
noreply at bugs.horde.org
Tue Sep 25 16:11:58 UTC 2018
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.
Ticket URL: https://bugs.horde.org/ticket/14857
------------------------------------------------------------------------------
Ticket | 14857
Updated By | Git Commit <commits at lists.horde.org>
Summary | Multiple XSS security vulnerabilities
Queue | Horde Groupware
Version | 5.2.22
Type | Bug
State | Assigned
Priority | 3. High
Milestone |
Patch |
Owners | Michael Rubinsky
------------------------------------------------------------------------------
Git Commit <commits at lists.horde.org> (2018-09-25 16:11) wrote:
Changes have been made in Git (FRAMEWORK_5_2):
commit ecea6ea740419e19122a50579ba2903c1cb71d7a
Author: Michael J Rubinsky <mrubinsk at horde.org>
Date: Tue, 25 Sep 2018 12:11:51 -0400
Bug: 14857
Escape user supplied $color value and prevent XSS vuln.
M lib/Horde/Core/Ui/VarRenderer/Html.php
https://github.com/horde/Core/commit/ecea6ea740419e19122a50579ba2903c1cb71d7a
More information about the bugs
mailing list