Skip to content

v2.79.6 - XSS Security Fix in Ticket Messages

Choose a tag to compare

@fotsakir fotsakir released this 21 Jan 09:43
· 43 commits to main since this release

What's New

Fixed

  • XSS Security Fix in Ticket Messages - Fixed HTML injection vulnerability in ticket detail page
    • Messages containing HTML tags (like <style>) were being rendered as actual HTML
    • Added |e (escape) filter before |replace to properly escape HTML entities
    • Prevents unclosed HTML tags from breaking page layout (e.g., sidebar disappearing)

Upgrade

cd /root
wget https://github.com/fotsakir/codehero/releases/latest/download/codehero-2.79.6.zip
unzip codehero-2.79.6.zip
cd codehero
sudo ./upgrade.sh