[MojoMojo] MojoMojo 0.999033 - Security hotfix (attachment deletion
fix)
Dan Dascalescu
ddascalescu at gmail.com
Fri Aug 14 12:55:32 GMT 2009
I have just uploaded to CPAN a new version of MojoMojo that fixes a
security breach whereby anonymous users could delete attachments *from
the attachments table*. The files were not physically deleted from the
filesystem.
If anyone was affected by this issue, please join #mojomojo on irc.perl.org.
In the meantime, upgrading to the new version is strongly encouraged.
Until it hits CPAN, see http://github.com/marcusramberg/mojomojo
Best regards,
Dan Dascalescu
More information about the Mojomojo
mailing list