friendica/src/Module/Admin
Hypolite Petovan 5c5d7eb04f
Fix several vulnerabilities (#13927)
* Escape HTML in the location field of a calendar event post

- This allowed script tags to be interpreted in the post display of an event.

* Add form security token check to /admin/phpinfo module

- This prevents basic XSS attacks against /admin/phpinfo

* Add form security token check to /babel module

- This prevents basic XSS attacks against /babel

* Prevent pass-through for attachments

- This addresses a straightforward Reflected XSS vulnerability if a malicious HTML/Javascript file is attached to a post through upload

* Prevent overwriting cid on event edit

- This allowed to share an event as any other user after zeroing the cid field of an existing event
2024-02-22 06:53:52 +01:00
..
Addons Friendica copyright changed from 2023 to 2034 2024-01-02 20:57:26 +00:00
Logs Friendica copyright changed from 2023 to 2034 2024-01-02 20:57:26 +00:00
Themes Friendica copyright changed from 2023 to 2034 2024-01-02 20:57:26 +00:00
DBSync.php Friendica copyright changed from 2023 to 2034 2024-01-02 20:57:26 +00:00
Features.php Friendica copyright changed from 2023 to 2034 2024-01-02 20:57:26 +00:00
Federation.php "ANY_VALUE" is removed 2024-01-15 16:45:24 +00:00
PhpInfo.php Fix several vulnerabilities (#13927) 2024-02-22 06:53:52 +01:00
Queue.php Friendica copyright changed from 2023 to 2034 2024-01-02 20:57:26 +00:00
Site.php Disallow mail addresses for registration (#13920) 2024-02-19 09:33:20 +01:00
Storage.php Friendica copyright changed from 2023 to 2034 2024-01-02 20:57:26 +00:00
Summary.php Friendica copyright changed from 2023 to 2034 2024-01-02 20:57:26 +00:00
Tos.php Friendica copyright changed from 2023 to 2034 2024-01-02 20:57:26 +00:00