On Fri, Jul 22, 2011 at 01:47:19PM +0200, Lukas Fleischer wrote:
> The file name displayed in the rename hint should be escaped to avoid
> XSS. Note that this vulnerability is only applicable when an attacker
> has gained push access to the repository.

Thanks, applied to stable.

--
larsh

_______________________________________________
cgit mailing list
[email protected]
http://hjemli.net/mailman/listinfo/cgit

Reply via email to