Releases: dereuromark/cakephp-feedback
Releases · dereuromark/cakephp-feedback
Release list
2.3.0
Fixes
- Stored XSS in admin listing.
templates/Admin/Feedback/listing.phpechoed several user-submitted fields without escaping:subject,feedback,screenshot(interpolated into animg srcdata URI), andurl(interpolated intohrefand link text whenFeedback.autoLinkis enabled). An attacker submitting feedback with HTML/JS in any of those fields got script execution in the admin panel that views the listing — admin-targeted stored XSS reachable by any user able to submit feedback. Now wraps each value inh(), and autoLink requires ahttp(s)://scheme sojavascript:/data:URLs are blocked even with the attribute escaped. Addedrel="noopener noreferrer"on the new-tab links. - XSS in
$name/$emailvalue attributes intemplates/element/sidebar.php. Both are sourced from session/AuthUserand any upstream component that lets an attacker influence those keys (e.g. an OAuth display name) reached every page rendering the widget unescaped. - Stored screenshot bytes echoed into
data:URIs acrossFeedback/index.php,Feedback/viewimage.php,Admin/Feedback/viewimage.php,Admin/FeedbackItems/{viewimage,view}.phpare now escaped. A submitter who replaced the legitimate base64 payload with attribute-breaking content otherwise persisted XSS for every user or admin who opened the feedback item.
Improvements
- Admin UI and frontend sidebar widget are now strict-CSP compatible. Replaced 6
Form->postLink+confirmcalls in admin templates withForm->postButton+data-confirm-message. Added nonce to inline<script>blocks in admin templates and the frontend sidebar widget (sourced from thecspNoncerequest attribute, falls back gracefully when no nonce is set). Replaced 3 inlineonclick="return false;"handlers in the sidebar element withtype="button"/data-feedback-nop+ delegated listener. After this release, templates have zero inlinestyle=attributes. - Switched all plugin-runtime
__()calls to__d('feedback', ...)so translations resolve through the plugin's own i18n domain. Refreshedresources/locales/feedback.pot(~8 years stale, 25 → 56 unique msgids) and switched to--no-locationfor tidier diffs on regeneration. Existingde/,es/,nl/,sv/packs are intentionally left for translators tomsgmergeagainst. - Raised PHP minimum version
Full Changelog: 2.2.1...2.3.0
2.2.1
2.2.0
What's Changed
- Fixed security vulnerabilities (RCE, Path Traversal, DoS)
Full Changelog: 2.1.0...2.2.0
2.1.0
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
Fixes
Fixed controller default model class.