• You need to sanitize the plugin. I was messing around with it and was able to inject a javascript into slimstat using the search field. You need to sanitize your script and fix the issue.

Viewing 12 replies - 1 through 12 (of 12 total)
  • Plugin Contributor Jason Crouse

    (@coolmann)

    Hi Mike, it would be quite helpful if you could contact me to address the issue together, instead of just giving me 1 star and disappearing like that. You may want to remember that I do all of this for free, and that the only reward is to get 5 stars for the work I do, so I think you can imagine how frustrating it is to see users like you, who come, trash my work and disappear πŸ™

    http://slimstat.duechiacchiere.it/contact-us/

    Thank you
    Camu

    Plugin Contributor Jason Crouse

    (@coolmann)

    I was able to replicate the issue, and a patch has been added to version 3.0 πŸ˜‰ Contact me if you want to test it in advance and see if the problem is fixed.

    Thank you,
    Camu

    Thread Starter mikes88

    (@mikes88)

    Didnt realize i gave it 1 star until it was too late. sorry about that. The plugin is pretty decent but that was a huge security breach for malicious code. Not sure how to change the rating if i can. but i would give this plugin at least a 3.5 or 4 stars.

    Plugin Contributor Jason Crouse

    (@coolmann)

    Just click on the stars again πŸ˜‰ As for the security breach, thank you for pointing that out, I will release the hotfix asap. Again, if you want to help me test it, feel free to contact me!

    Best,
    Camu

    Thread Starter mikes88

    (@mikes88)

    How long until the plugin will be avail for download?

    Plugin Contributor Jason Crouse

    (@coolmann)

    A few hours, I would say…

    Plugin Contributor Jason Crouse

    (@coolmann)

    Released. Test it and let me know how it goes. Please note that this is a temporary hotfix, version 3.0 will have a more robust code in place πŸ˜‰

    Cheers,
    Camu

    Thread Starter mikes88

    (@mikes88)

    i have the 2 files edited to fix the issue. is there an email i can send them too so you can compare the files?

    Plugin Contributor Jason Crouse

    (@coolmann)

    So you’re saying that version 2.9.5 doesn’t fix the problem for you? Contact me at the URL above, and I’ll get in touch with you

    Plugin Contributor Jason Crouse

    (@coolmann)

    Well?

    Thread Starter mikes88

    (@mikes88)

    everything seems to be working.

    Plugin Contributor Jason Crouse

    (@coolmann)

    Okay, thanks.

Viewing 12 replies - 1 through 12 (of 12 total)

The topic ‘Sanitize the plugin’ is closed to new replies.