Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prevents cross-site scripting (XSS) in the parameter username, Error messages now multilingual #261

Merged
merged 9 commits into from
Oct 2, 2023

Conversation

Fraenkiman
Copy link
Collaborator

@Fraenkiman Fraenkiman commented Aug 31, 2023

Prevents cross-site scripting (XSS) in the FlatPress installer in the parameter username

Many thanks for the tip to Parag Bagul -> #220

- Username can only contain letters, numbers and 1 underscore.
- Error messages are now supported in multiple languages
@Fraenkiman Fraenkiman changed the title Update main.lib.php Prevents cross-site scripting (XSS) in the parameter username, Error messages now multilingual Sep 1, 2023
@Fraenkiman Fraenkiman mentioned this pull request Oct 2, 2023
@Fraenkiman Fraenkiman merged commit a4fe75d into flatpressblog:master Oct 2, 2023
@Fraenkiman Fraenkiman deleted the upstream/issue220 branch October 2, 2023 13:51
@paragbagul111
Copy link

Dear @Fraenkiman

I am reaching out to inquire about the assignment of a CVE number for the vulnerability I reported. Kindly review the details on the Huntr platform: Vulnerability Report. I kindly request the assignment of a CVE for the patched vulnerabilities.

Alternatively, if there is a process for requesting a CVE directly from CVE Mitre, please provide guidance on how I can proceed.

Thank you for your attention to this matter.

Best Regards,
Parag Bagul

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Error messages are not translated during setup.
2 participants