github getgrav/grav-plugin-form 9.1.8

4 hours ago

Bugfix

  • Security: the form save action now rejects a folder setting that tries to escape the data directory, preventing form files from being written elsewhere on disk.
  • Security: the form save action now re-checks the filename after template processing, so submitted form values can no longer turn it into a disallowed file type or a path outside the data directory.

Don't miss a new grav-plugin-form release

NewReleases is sending notifications on new releases.