Home
last modified time | relevance | path

Searched hist:f23f95941a400702f525923973f3612df6da82cb (Results 1 – 1 of 1) sorted by relevance

/dokuwiki/lib/plugins/usermanager/
H A Dadmin.phpf23f95941a400702f525923973f3612df6da82cb Wed Mar 18 21:16:34 UTC 2015 Andreas Gohr <andi@splitbrain.org> SECURITY escape user properties in user manager #1081

The user properties (login, real name, etc) where not properly escaped
in the user manager's edit form. This allowed a XSS attack on the
superuser by registered users.

Thanks to Filippo Cavallarin from www.segment.technology for discovering
this bug.