Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update config.php #9

Merged
merged 1 commit into from
Jul 6, 2017
Merged

Update config.php #9

merged 1 commit into from
Jul 6, 2017

Conversation

passtion
Copy link
Contributor

@passtion passtion commented Jul 6, 2017

Fix xss vulnerability by sun@yuesec.com

Fix xss vulnerability by sun@yuesec.com
@andrzuk andrzuk merged commit d422cbd into andrzuk:master Jul 6, 2017
@andrzuk
Copy link
Owner

andrzuk commented Jul 6, 2017

Thanks for update! I didn't protect these fields of POST because I assumed that only admin (as responsible person) has access to Config module. No common user has access to it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants