Fix XSS vulnerability in message subject handling using Larry skin (#1488519)
| | |
| | | CHANGELOG Roundcube Webmail |
| | | =========================== |
| | | |
| | | - Fix XSS vulnerability in message subject handling using Larry skin (#1488519) |
| | | - Fix handling of links with various URI schemes e.g. "skype:" (#1488106) |
| | | - Fix handling of links inside PRE elements on html to text conversion |
| | | - Fix indexing of links on html to text conversion |
| | |
| | | |
| | | // single header value is requested |
| | | if (!empty($attrib['valueof'])) |
| | | return Q($plugin['output'][$attrib['valueof']]['value'], ($hkey == 'subject' ? 'strict' : 'show')); |
| | | return Q($plugin['output'][$attrib['valueof']]['value'], ($attrib['valueof'] == 'subject' ? 'strict' : 'show')); |
| | | |
| | | // compose html table |
| | | $table = new html_table(array('cols' => 2)); |