| Name |
Last commit
|
Last update |
|---|---|---|
| .. | ||
| management | ||
| README | ||
| __init__.py | ||
| makoloader.py | ||
| middleware.py | ||
| shortcuts.py | ||
| startup.py | ||
| template.py | ||
| templatetag_helpers.py | ||
| tests.py |
Several templates used a variable set by the user (the request host header). This led to a vulnerability where an attacker could inject their domain name into these templates (i.e., activation emails). This patch fixes this vulnerability. LMS-532
| Name |
Last commit
|
Last update |
|---|---|---|
| .. | ||
| management | Loading commit data... | |
| README | Loading commit data... | |
| __init__.py | Loading commit data... | |
| makoloader.py | Loading commit data... | |
| middleware.py | Loading commit data... | |
| shortcuts.py | Loading commit data... | |
| startup.py | Loading commit data... | |
| template.py | Loading commit data... | |
| templatetag_helpers.py | Loading commit data... | |
| tests.py | Loading commit data... |