8000 Fix xss trough media item title in datagrid by carakas · Pull Request #3401 · forkcms/forkcms · GitHub
[go: up one dir, main page]

Skip to content

Fix xss trough media item title in datagrid#3401

Merged
carakas merged 1 commit intoforkcms:masterfrom
justcarakas:fix-xss-in-media-library
May 16, 2021
Merged

Fix xss trough media item title in datagrid#3401
carakas merged 1 commit intoforkcms:masterfrom
justcarakas:fix-xss-in-media-library

Conversation

@carakas
Copy link
Member
@carakas carakas commented May 16, 2021

Type

  • Security

Resolves the following issues

Pull request description

It was possible to perform an xss attack by changing the title of a media item. When building the media item datagrid that javascript in the title of the item would be executed

@carakas carakas added this to the 5.10.0 milestone May 16, 2021
@carakas carakas requested a review from a team as a code owner May 16, 2021 15:25
@carakas carakas merged commit 5030073 into forkcms:master May 16, 2021
@carakas carakas deleted the fix-xss-in-media-library branch May 16, 2021 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

0