MojoMojo 0.999033 - Security hotfix (attachment deletion fix)

1 message Options
Embed this post
Permalink
dandv

MojoMojo 0.999033 - Security hotfix (attachment deletion fix)

Reply Threaded More More options
Print post
Permalink
I have just uploaded to CPAN a new version of MojoMojo that fixes a
security breach whereby anonymous users could delete attachments *from
the attachments table*. The files were not physically deleted from the
filesystem.

If anyone was affected by this issue, please join #mojomojo on irc.perl.org.

In the meantime, upgrading to the new version is strongly encouraged.
Until it hits CPAN, see http://github.com/marcusramberg/mojomojo


Best regards,
Dan Dascalescu

_______________________________________________
Mojomojo mailing list
[hidden email]
http://lists.scsys.co.uk/cgi-bin/mailman/listinfo/mojomojo