[SECURITY] XSS in belog module
The username of a backend user and title of a workspace record miss accordant escaping if being rendered in the belog module. Since this has only impact on admin users in the backend, the fix is handled in public instead of a security release. Resolves: #72475 Releases: master, 7.6, 6.2 Change-Id: Ib165f8ef849a641984fc5fb834b30983f7b63a54 Reviewed-on: https://review.typo3.org/45519 Reviewed-by:Markus Klein <markus.klein@typo3.org> Tested-by:
Markus Klein <markus.klein@typo3.org> Reviewed-by:
Morton Jonuschat <m.jonuschat@mojocode.de> Tested-by:
Morton Jonuschat <m.jonuschat@mojocode.de>
Showing
- typo3/sysext/belog/Classes/ViewHelpers/UsernameViewHelper.php 2 additions, 2 deletions...3/sysext/belog/Classes/ViewHelpers/UsernameViewHelper.php
- typo3/sysext/belog/Classes/ViewHelpers/WorkspaceTitleViewHelper.php 2 additions, 2 deletions...xt/belog/Classes/ViewHelpers/WorkspaceTitleViewHelper.php
Please register or sign in to comment