github timothepoznanski/poznote 6.68.6
Release 6.68.6

4 hours ago

🔒 Security: the restore / import feature no longer executes the SQL dump of a backup archive as-is. The dump is now parsed and only the statements a Poznote backup is made of are accepted, which closes a critical vulnerability (GHSA-rmm5-6582-qcmc) that allowed any authenticated user to escalate privileges or run code on the server. Thanks to @xSlePs for the responsible disclosure.

Don't miss a new poznote release

NewReleases is sending notifications on new releases.