From 51475b41b1912087ed08b02e79f573d7637073ef Mon Sep 17 00:00:00 2001 From: Starbeamrainbowlabs Date: Fri, 3 Sep 2021 02:25:58 +0100 Subject: [PATCH] Update Changelog --- Changelog.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Changelog.md b/Changelog.md index 1461cd2..e295aca 100644 --- a/Changelog.md +++ b/Changelog.md @@ -24,7 +24,7 @@ This file holds the changelog for Pepperminty Wiki. This is the master list of t ## Fixed - [security] Fixed some potential XSS attacks in the page editor - [security] Fix stored XSS attack in the wiki name via the first run wizard [CVE-2021-38600](https://github.com/hmaverickadams/CVE-2021-38600); low severity since it requires the site secret to do the initial setup & said initial setup can only be performed once - - [security] Fix reflected XSS attack (arbitrary code execution in the user's browser) via the many different GET parameters + - [security] Fix reflected XSS attacks (arbitrary code execution in the user's browser due to unsanitized data) via the many different GET parameters in many different modules - [security] Automatically run page titles through `htmlentities()` - Fixed a weird bug in the `stats-update` action causing warnings - search: Properly apply weightings of matches in page titles and tags