<
8000
div style="--spacing:var(--spacing-none)" class="prc-PageLayout-PageLayoutRoot--KH-d" data-has-sidebar="true">
carakas
force-pushed
the
more-security-fixes
branch
from
June 27, 2020 00:27
Merged
Conversation
04d6bed to
2e13cf4
Compare
src/Backend/Modules/ContentBlocks/Domain/ContentBlock/ContentBlockDataGrid.php
Show resolved
Hide resolved
jessedobbelaere
approved these changes
Jul 1, 2020
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Type
Resolves the following issues
My mailbox overflowing by pen testers that all report a different variant of the same issue
Pull request description
First of all, this is not a huge security issue as long as the people that have access to the backend can be trusted.
But since you never know when you have somebody trying out some nasty stuff or using an unsafe password and someone else gains access to an account with a limited set of rights this PR will prevent them from trying to steal admin passwords or executing code as a different user through stored xss
Also changed the default of serialised data not allowing any classes in it since it can be abused as well