Changeset 3219730
- Timestamp:
- 01/09/2025 03:42:11 PM (14 months ago)
- Location:
- trackserver/trunk
- Files:
-
- 3 edited
-
class-trackserver-shortcode.php (modified) (2 diffs)
-
readme.txt (modified) (2 diffs)
-
trackserver.php (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trackserver/trunk/class-trackserver-shortcode.php
r2860786 r3219730 107 107 $class_str = ''; 108 108 if ( count( $classes ) ) { 109 $class_str = 'class="' . implode( ' ', $classes) . '"';109 $class_str = 'class="' . esc_attr( implode( ' ', $classes ) ) . '"'; 110 110 } 111 111 … … 329 329 $class_str = ''; 330 330 if ( $atts['class'] ) { 331 $class_str = 'class="' . htmlspecialchars( $atts['class'] ) . '"';331 $class_str = 'class="' . esc_attr( $atts['class'] ) . '"'; 332 332 } 333 333 -
trackserver/trunk/readme.txt
r3151401 r3219730 4 4 Tags: gps, gpx, map, leaflet, track, mobile, tracking 5 5 Requires at least: 4.7 6 Tested up to: 6. 66 Tested up to: 6.7 7 7 Stable tag: trunk 8 8 License: GPLv2 or later … … 266 266 267 267 == Changelog == 268 269 = v5.0.3 = 270 Release date: 09 January 2025 271 272 Fixed: 273 * XSS in the 'tsmap' shortcode handler (CVE-2024-12505). 268 274 269 275 = v5.0.2 = -
trackserver/trunk/trackserver.php
r2874962 r3219730 6 6 Plugin URI: https://www.grendelman.net/wp/trackserver-wordpress-plugin/ 7 7 Description: GPS Track Server for TrackMe, OruxMaps and others 8 Version: 5.0. 28 Version: 5.0.3 9 9 Author: Martijn Grendelman 10 10 Author URI: http://www.grendelman.net/ … … 14 14 15 15 === RELEASE HISTORY === 16 2025-01-09 - v5.0.3 - fix XSS in shortcode, reported by yudha @ Wordfence 16 17 2023-03-05 - v5.0.2 - Bugfix 17 18 2023-02-06 - v5.0 - new features, code refactoring, leaflet 1.9.3
Note: See TracChangeset
for help on using the changeset viewer.