- limit the
update-check.cgi
to parse forcmd=download
and not parse arbitrary query string options.
Full Changelog: 1.10...1.11
2ba6f5694f21715d3d12a2ff7529661ee087e97899dca117d635b63f1ed8b4a8 scriptparser-1.11.tar.gz
- implemented a sessionID (sid) check for exec.cgi which checks for a valid sessionID before executing any rega script code (#4, CVE-2019-18937, @jens-maus).
- maintenance changes to comply with homematic-community home (@jens-maus).
fixed charset issue in device names with german umlaut, removed link … …to telnet howto because of 404, added security message
fixed problem with update-check.cgi not returning a Content-Type: for the version number query.
…tion on hm-docker-amd64