From e1f9458db145ce8ffda195ab78e3ba2260ea1f8a Mon Sep 17 00:00:00 2001 From: Ingo Schommer Date: Tue, 24 Sep 2013 14:18:45 +0200 Subject: [PATCH] Added 3.0.7 changelog --- docs/en/changelogs/3.0.7.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 docs/en/changelogs/3.0.7.md diff --git a/docs/en/changelogs/3.0.7.md b/docs/en/changelogs/3.0.7.md new file mode 100644 index 000000000..700a1b42e --- /dev/null +++ b/docs/en/changelogs/3.0.7.md @@ -0,0 +1,17 @@ +# 3.0.7 + +## Overview + +### Security: XSS in form validation errors (SS-2013-008) + +See [announcement](http://www.silverstripe.org/ss-2013-008-xss-in-numericfield-validation/) + +### Security: XSS in CMS "Pages" section (SS-2013-009) + +See [announcement](http://www.silverstripe.org/ss-2013-009-xss-in-cms-pages-section/) + +### API: Form validation message no longer allow HTML + +Due to cross-site scripting concerns when user data is used for form messages, +it is no longer possible to use HTML in `Form->sessionMessage()`, and consequently +in the `FormField->validate()` API. \ No newline at end of file