Mitch Phillips

Results 3 issues of Mitch Phillips

$dash_intro_text is initialised on `init.php:28` from an untrusted $_GET source. This value is used only in `pages/admin.settings.php:239`. This variable normally contains the markup text from the WYSIWYG editor in the...

type: enhancement
p: high
s: in progress
semver: minor

SourceBans++ web panel has inadequate [XSRF](https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)) protection. Administrators that are coerced or inadvertently exposed to malicious code may inadvertently allow an attacker to have full access to almost all of...

type: enhancement
s: in progress
p: critical
semver: minor

MemtagABI is an AArch64 ELF ABI extension that allows for tagging of stack, heap, and global variables. The ABI includes: 1. Dynamic array entries for instructing the dynamic loader to...