Release v2.0.2 - Fix HTML injection/XSS vulnerability in filenames of attached files #1694
elrido
announced in
Announcements
Replies: 1 comment 3 replies
-
|
Thanks for the patch! I'd suggest to add a big red banner to the release changelog of all affected versions in https://github.com/PrivateBin/PrivateBin/releases saying that the version is vulnerable to injection and should be avoided. |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
This release addresses an issue with the lacking sanitation of file names when displaying attached files. This issue affects instances that enable fileupload. More details on this issue can be found in the security advisory.
This discussion was created from the release Release v2.0.2 - Fix HTML injection/XSS vulnerability in filenames of attached files.
Beta Was this translation helpful? Give feedback.
All reactions