Sitelet https://github.com/dereuromark/cakephp-feedback/releases
Skip to content

Releases: dereuromark/cakephp-feedback

2.3.0

Choose a tag to compare

@dereuromark dereuromark released this 05 May 01:49
95c27af

Fixes

  • Stored XSS in admin listing. templates/Admin/Feedback/listing.php echoed several user-submitted fields without escaping: subject, feedback, screenshot (interpolated into an img src data URI), and url (interpolated into href and link text when Feedback.autoLink is enabled). An attacker submitting feedback with HTML/JS in any of those fields got script execution in the admin panel that views the listing — admin-targeted stored XSS reachable by any user able to submit feedback. Now wraps each value in h(), and autoLink requires a http(s):// scheme so javascript: / data: URLs are blocked even with the attribute escaped. Added rel="noopener noreferrer" on the new-tab links.
  • XSS in $name / $email value attributes in templates/element/sidebar.php. Both are sourced from session/AuthUser and any upstream component that lets an attacker influence those keys (e.g. an OAuth display name) reached every page rendering the widget unescaped.
  • Stored screenshot bytes echoed into data: URIs across Feedback/index.php, Feedback/viewimage.php, Admin/Feedback/viewimage.php, Admin/FeedbackItems/{viewimage,view}.php are now escaped. A submitter who replaced the legitimate base64 payload with attribute-breaking content otherwise persisted XSS for every user or admin who opened the feedback item.

Improvements

  • Admin UI and frontend sidebar widget are now strict-CSP compatible. Replaced 6 Form->postLink + confirm calls in admin templates with Form->postButton + data-confirm-message. Added nonce to inline <script> blocks in admin templates and the frontend sidebar widget (sourced from the cspNonce request attribute, falls back gracefully when no nonce is set). Replaced 3 inline onclick="return false;" handlers in the sidebar element with type="button" / data-feedback-nop + delegated listener. After this release, templates have zero inline style= attributes.
  • Switched all plugin-runtime __() calls to __d('feedback', ...) so translations resolve through the plugin's own i18n domain. Refreshed resources/locales/feedback.pot (~8 years stale, 25 → 56 unique msgids) and switched to --no-location for tidier diffs on regeneration. Existing de/, es/, nl/, sv/ packs are intentionally left for translators to msgmerge against.
  • Raised PHP minimum version

Full Changelog: 2.2.1...2.3.0

2.2.1

Choose a tag to compare

@dereuromark dereuromark released this 06 Jan 23:38

Improvements

  • Add configurable sessionKey
  • Migrations v5 compatibility

Full Changelog: 2.2.0...2.2.1

2.2.0

Choose a tag to compare

@dereuromark dereuromark released this 24 Nov 22:30
fa7e98b

What's Changed

  • Fixed security vulnerabilities (RCE, Path Traversal, DoS)

Full Changelog: 2.1.0...2.2.0

2.1.0

Choose a tag to compare

@dereuromark dereuromark released this 04 Nov 03:56

Improvements

  • Removed deprecations

Full Changelog: 2.0.5...2.1.0

2.0.5

Choose a tag to compare

@dereuromark dereuromark released this 16 Sep 20:55

Fixes

  • Fixed Auth user ID detection

2.0.4

Choose a tag to compare

@dereuromark dereuromark released this 20 Mar 11:53

Fixes

  • Fixed up files bundled in release using gitattributes file.

Full Changelog: 2.0.3...2.0.4

2.0.3

Choose a tag to compare

@dereuromark dereuromark released this 23 Jan 06:34

Fixes

Fixed plugin class name

2.0.2

Choose a tag to compare

@dereuromark dereuromark released this 21 Dec 00:15

Fixes

Fix up Bootstrap 5 compatibility.

2.0.1

Choose a tag to compare

@dereuromark dereuromark released this 05 Dec 19:10

Fixes

Fixed controller default model class.

2.0.0

Choose a tag to compare

@dereuromark dereuromark released this 12 Oct 23:41

CakePHP 5 compatible release

Enjoy!