github sbrl/Pepperminty-Wiki v0.15.1

latest releases: v0.24, v0.24-beta1, v0.23...
6 years ago

This is a small patch that fixes an authenticated denial-of-service attack when uploading a malicious SVG. I'd advise patching now - simply obtain a new copy of index.php via any of the usual methods described in the main README.

It also brings a teensy new feature to file preview pages, and finally fixes a nasty bug whereby strange things would happen if you tried to save an edit to a page with an ampersand in its name.

Added

  • Added an input box with auto-generated short markdown embed code with copy button to file pages

Changed

  • Added 1920 as a preset image size on file pages

Fixed

  • Fix saving edits to pages with an ampersand in their name (#99)
  • [Security] Fixed an authenticated denial-of-service attack when uploading a malicious SVG (ref XXE billion laughs attack, #152)

Don't miss a new Pepperminty-Wiki release

NewReleases is sending notifications on new releases.