CMS Made Simple Core

Jump to Bug #
ID Summary Open Date Severity Version Resolution State Assigned To Submitted By
11762 Administrator Password Reset Poisoning by host header attack 2018-03-03 Minor Fixed Open Nobody reklawetihwx
11769 design manager - stylesheet - new stylesheet doesn't set design value 2018-03-14 Trivial 2.2.7 None Open Nobody Andrzej
11788 CMS Made Simple forum register 2018-04-05 None Accepted Open Nobody Peter Tindemans
11807 UserOperations::IsSuperuser() calls UserOperations::GetMemberGroups() incorrectly 2018-05-01 Minor 2.2.7 Fixed Open Nobody Chris
11822 cms_stylesheet name attribute uses LIKE in query (with solution) 2018-05-17 Major 2.2.7 None Open Mathieu Muths (airelibre) Victor Avgust
11829 system information, tabindex and accesskey issues (resolutions include) 2018-06-01 Minor 2.2.7 None Open Mathieu Muths (airelibre) Philippe Thomas
11831 Filepicker profile path issue when root_url defined in config 2018-06-05 None 2.2.7 None Open Nobody Matt Hornsby (DIGI3)
11832 File manger inconsistent on stripping whitespace 2018-06-12 Minor 2.2.7 None Open Nobody stephen cooper
11848 multiple reflected and stored XSS's in 2.2.7 installation process 2018-06-25 Critical 2.2.7 Won't Fix Open Nobody sriaknth
11870 Duplicating page shows content type but doesn't allow changing it 2018-08-04 Trivial 2.2.7 None Open Nobody Matt Hornsby (DIGI3)
11871 XSS (via svg file upload) 2018-08-08 Major 2.2.8 Invalid Open Nobody Provensec Security
11874 Design import not assigning correct owner 2018-08-18 None 2.2.8 None Open Nobody Matt Hornsby (DIGI3)