yii2-file-upload-widget icon indicating copy to clipboard operation
yii2-file-upload-widget copied to clipboard

Zero-day in jQuery-File-Upload

Open MarcoPro opened this issue 7 years ago • 1 comments

A vulnerability has been discovered. It is recommended to update the plugin version.

https://www.zdnet.com/article/zero-day-in-popular-jquery-plugin-actively-exploited-for-at-least-three-years/?utm_campaign=Security%2BNewsletter&utm_medium=email&utm_source=Security_Newsletter_co_100

In addition there is another possible vulnerability that is described in the blueimp / jQuery-File-Upload website that is corrected with the version v9.25.1 Mitigates some Potential vulnerabilities with PHP+ImageMagick.

MarcoPro avatar Oct 26 '18 12:10 MarcoPro

imagen

MarcoPro avatar Oct 26 '18 12:10 MarcoPro