pkgsrc/www/contao44
taca 6c2c7d52aa www/contao44: update to 4.4.18
Contao 4.4.17 (2018-04-04)

Contao version 4.4.17 is available.  The bugfix release fixes a few minor
issues including a problem with rendering custom layout sections.


Contao 4.4.18 (2018-04-18)

Contao version 4.4.18 is available.  The bugfix release fixes an XSS
vulnerability in the system log of the back end (CVE-2018-10125).

CVE-2018-10125

With a manipulated request, an attacker can implant a script which is executed
when a logged in back end user opens the system log.  The attacker themselves
does not have to be logged in.

The problem affects Contao 3.0.0 to 3.5.34, 4.0.0 to 4.4.17 and 4.5.0 to
4.5.7. We highly recommend you to update.
2018-04-23 14:19:00 +00:00
..
DEINSTALL
DESCR Update contao44 to 4.4.2. 2017-07-31 13:46:34 +00:00
distinfo www/contao44: update to 4.4.18 2018-04-23 14:19:00 +00:00
INSTALL
Makefile www/contao44: update to 4.4.18 2018-04-23 14:19:00 +00:00
MESSAGE
PLIST www/contao44: update to 4.4.18 2018-04-23 14:19:00 +00:00