escape rev and search to avoid XSS breach#229
escape rev and search to avoid XSS breach#229Badatos wants to merge 1 commit intowebsvnphp:masterfrom
Conversation
|
The original issue lists several other spots. Did you test then or simply limit your PR for this file? |
|
I don't know exactly how many gaps this PR fills, but at least all files that use createSearchSelectionForm. I've tested on |
|
I meant these #228 (comment) |
These aren't confirmed vulnerabilities, but rather leads to follow. |
|
Tested also on URL like this : And the same fix corrects it ;) |
Hello,
I think theses small changes will prevent some XSS breach issued in #228