summaryrefslogtreecommitdiff
path: root/inc/lang/it
diff options
context:
space:
mode:
authorAndreas Gohr <gohr@cosmocode.de>2013-12-10 15:56:06 +0100
committerAndreas Gohr <gohr@cosmocode.de>2013-12-10 15:56:06 +0100
commit9e8bcd5f2ba2246ad2dff46d0313cb0c9e9f5579 (patch)
tree069bb6a219bdbf0f29b1ef4d9816f278f65236e8 /inc/lang/it
parent8c4759c9d38a21eb352498a8035944ee019e7738 (diff)
downloadrpg-9e8bcd5f2ba2246ad2dff46d0313cb0c9e9f5579.tar.gz
rpg-9e8bcd5f2ba2246ad2dff46d0313cb0c9e9f5579.tar.bz2
fix possible XSS vulnerability in Plugin Manager
The plugin manager echos raw URLs in error messages, this could allow to construct an XSS attack. However the affected form is CSRF protected, so an attacker would require another XSS vulnerability to get the needed token, rendering this attack unneeded. So this should not be exploitable.
Diffstat (limited to 'inc/lang/it')
0 files changed, 0 insertions, 0 deletions