[tryton-announces] Security Release for issue9394

2021-10-09 Thread News - Tryton Discussion: ced
Security Release for issue9394 Synopsis A vulnerability in sao has been found by Cédric Krier. With issue9394, the web client does not escape the HTML tags from user data. This allows cross-site scripting attacks which can result in session hijacking, persistent phishing attacks, and

[tryton-announces] Security Release for issue9394

2020-06-30 Thread News - Tryton Discussion: ced
Security Release for issue9394 Synopsis A vulnerability in sao has been found by Cédric Krier. With issue9394, the web client does not escape the HTML tags from user data. This allows cross-site scripting attacks which can result in session hijacking, persistent phishing attacks, and