Summary: | KMail QML HTML injection via --subject and --attach | ||
---|---|---|---|
Product: | [Applications] kmail2 | Reporter: | Benjamin Flesch <benjaminflesch> |
Component: | composer | Assignee: | kdepim bugs <kdepim-bugs> |
Status: | REPORTED --- | ||
Severity: | normal | CC: | montel |
Priority: | NOR | ||
Version: | unspecified | ||
Target Milestone: | --- | ||
Platform: | Other | ||
OS: | Linux | ||
Latest Commit: | Version Fixed In: | ||
Sentry Crash Report: |
Description
Benjamin Flesch
2024-01-22 22:11:08 UTC
Git commit a10fca4cb4d16440db694a9e007186c1230eba69 by Laurent Montel. Committed on 23/01/2024 at 06:59. Pushed by mlaurent into branch 'release/24.02'. Don't insert HTML in subject M +2 -2 src/editor/kmcomposerwin.cpp https://invent.kde.org/pim/kmail/-/commit/a10fca4cb4d16440db694a9e007186c1230eba69 Git commit 3442628448349d1f12d97a28efc397d5e08c3001 by Laurent Montel. Committed on 23/01/2024 at 07:01. Pushed by mlaurent into branch 'master'. Don't insert HTML in subject M +2 -2 src/editor/kmcomposerwin.cpp https://invent.kde.org/pim/kmail/-/commit/3442628448349d1f12d97a28efc397d5e08c3001 For subject I fixed it. For attachment, I don't see how I can fix it... A possibly relevant merge request was started @ https://invent.kde.org/frameworks/kio/-/merge_requests/1574 A possibly relevant merge request was started @ https://invent.kde.org/pim/kmail/-/merge_requests/123 Git commit d67a5362a28c1e8fbca2e115b4154c09adb6ec43 by Carl Schwan. Committed on 12/03/2024 at 20:06. Pushed by carlschwan into branch 'master'. Fix HTML injection in externally added warning widget M +13 -2 src/editor/warningwidgets/attachmentaddedfromexternalwarning.cpp https://invent.kde.org/pim/kmail/-/commit/d67a5362a28c1e8fbca2e115b4154c09adb6ec43 Git commit f09e83b3b91637fe3b5812e50fd796b7fb78a7f6 by Carl Schwan. Committed on 12/03/2024 at 20:07. Pushed by carlschwan into branch 'release/24.02'. Fix HTML injection in externally added warning widget (cherry picked from commit d67a5362a28c1e8fbca2e115b4154c09adb6ec43) M +13 -2 src/editor/warningwidgets/attachmentaddedfromexternalwarning.cpp https://invent.kde.org/pim/kmail/-/commit/f09e83b3b91637fe3b5812e50fd796b7fb78a7f6 |