Fix XSS vulnerability in handling of text/enriched messages (#1488806)
| | |
| | | CHANGELOG Roundcube Webmail |
| | | =========================== |
| | | |
| | | - Fix XSS vulnerability in handling of text/enriched messages (#1488806) |
| | | - Fix handling of 'media' attribute on linked css (#1488789) |
| | | - Fix excessive LFs at the end of composed message with top_posting=true (#1488797) |
| | | - Option to display attached images as thumbnails below message body |
| | |
| | | else if ($data['type'] == 'enriched') { |
| | | $part->ctype_secondary = 'html'; |
| | | require_once(INSTALL_PATH . 'program/lib/enriched.inc'); |
| | | $body = Q(enriched_to_html($data['body']), 'show'); |
| | | $body = enriched_to_html($data['body']); |
| | | $body = rcmail_wash_html($body, $data, $part->replaces); |
| | | $part->ctype_secondary = 'html'; |
| | | } |
| | | else { |
| | | // assert plaintext |