diff --git a/docs/en/changelogs/3.0.7.md b/docs/en/changelogs/3.0.7.md new file mode 100644 index 000000000..700a1b42e --- /dev/null +++ b/docs/en/changelogs/3.0.7.md @@ -0,0 +1,17 @@ +# 3.0.7 + +## Overview + +### Security: XSS in form validation errors (SS-2013-008) + +See [announcement](http://www.silverstripe.org/ss-2013-008-xss-in-numericfield-validation/) + +### Security: XSS in CMS "Pages" section (SS-2013-009) + +See [announcement](http://www.silverstripe.org/ss-2013-009-xss-in-cms-pages-section/) + +### API: Form validation message no longer allow HTML + +Due to cross-site scripting concerns when user data is used for form messages, +it is no longer possible to use HTML in `Form->sessionMessage()`, and consequently +in the `FormField->validate()` API. \ No newline at end of file