From eb433aa33cec00b42eba3153fc905ebef9c6fd0b Mon Sep 17 00:00:00 2001 From: Aleksander Machniak Date: Thu, 17 Oct 2013 10:17:32 +0200 Subject: Fix vulnerability in handling _session argument of utils/save-prefs (#1489382) Conflicts: CHANGELOG program/lib/Roundcube/rcube_plugin_api.php program/steps/utils/save_pref.inc --- program/include/rcube_plugin_api.php | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) (limited to 'program/include') diff --git a/program/include/rcube_plugin_api.php b/program/include/rcube_plugin_api.php index 61bab3ce9..a1e634a4f 100644 --- a/program/include/rcube_plugin_api.php +++ b/program/include/rcube_plugin_api.php @@ -30,13 +30,14 @@ class rcube_plugin_api { static private $instance; - + public $dir; public $url = 'plugins/'; public $output; public $config; - public $allowed_prefs = array(); - + public $allowed_prefs = array(); + public $allowed_session_prefs = array(); + public $handlers = array(); private $plugins = array(); private $tasks = array(); -- cgit v1.2.3