[PATCH] lib: remove ineffective html_escape implementation, use escape instead

2015-04-13 Thread Andrew Shadura
# HG changeset patch # User Andrew Shadura and...@shadura.me # Date 1428965992 -7200 # Tue Apr 14 00:59:52 2015 +0200 # Node ID abeb4a96c92a913b61e2fcb9c9c87f4d02ea00a2 # Parent caef25781d8cb4b9e43e0def6b7a199c3f3cb462 lib: remove ineffective html_escape implementation, use escape instead

Re: [SECURITY ISSUE] CVE-2015-0276: Lack of CSRF attack protection enables gaining unauthorised access to users' accounts

2015-04-13 Thread Mads Kiilerich
On 04/10/2015 01:28 PM, Kallithea Security Team wrote: Dear users, We've discovered a security issue in Kallithea. We forgot to mention: Thanks to Paul van Empelen for reporting the issue. /Mads ___ kallithea-general mailing list