simplenews 6.x-2.0-alpha6

Security update

This is a maintenance release for Simplenews 6.x-2.x that includes a number of bugfixes including a fix for a security issue, see SA-CONTRIB-2013-080 -Simple News - Cross Site Scripting (XSS) for details.

Changes since 6.x-2.0-alpha5:

  • by Berdir: Fixed subscriber mail is not run through check_plain() on overview.
  • Fixed subscriptions' 'Activated' Views filter

simplenews 6.x-1.5

Security update

This is a maintenance release for Simplenews 6.x-1.x that includes a number of bugfixes including a fix for a security issue, see SA-CONTRIB-2013-080 -Simple News - Cross Site Scripting (XSS) for details.

Changes since 6.x-1.4:

  • by Berdir: Fixed subscriber mail is not run through check_plain() on overview.
  • #1387648 by anrikun: Fixed Sender name is MIME-encoded twice.

context 6.x-3.2

Security update

* Vulnerability one - remote code execution possibility through json_decode implementation in the block reaction. This update removes the implementation in the block reaction and you will need to ensure your version of PHP included a json_decode function before applying.

context 7.x-3.0

Security update
Bug fixes
Insecure

This release of Context addresses two security vulnerabilities and a bug introduced in rc1.

Pages

Subscribe with RSS Subscribe to RSS - Security update