Skip to content

Conversation

@gocom
Copy link
Contributor

@gocom gocom commented Mar 1, 2019

  • Fixes persistent XSS vulnerabilities.
  • Fixes recent forum posts list.
  • Cleans unnecessary variable naming; the blocks are evaluated in separate function context and do not collide.

This fixes potential of persistent XSS attacks.

Also fixes fetching forum topics and corrects the validation logic.
Cleans unnecessary variable naming; the blocks are evaluated in
separate function context and do not collide.
@gocom gocom changed the title Sanitize remote variables and fix remote forum post list Sanitize remote variables and fix recent forum post list Mar 1, 2019
@philwareham
Copy link
Member

This is great, thank you very much @gocom. I'll merged this and the other PR into the code and put live. My PHP skills are pretty much zero so I appreciate any help given there!

@philwareham philwareham merged commit 8bb307e into textpattern:master Mar 4, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants