Hi,
around 1.2.5, the upload postlet was AFAIR considered a security risk and we were advised to delete the whole folder.
In 1.4 the folder is still in the default installation.
Did I miss anything? Is the postlet now considered secure?
If not, why does CMSMS still ship with it?
Cheers,
Alex
Filemanager postlet still considered risky?
Re: Filemanager postlet still considered risky?
Postlet is still shipped but it is empty (dummy files). This is due to upgrade: empty postlet files overwrite old "risky" versions.faglork wrote: Did I miss anything? Is the postlet now considered secure?
If not, why does CMSMS still ship with it?
Cheers,
Alex
Regards
blast
Re: Filemanager postlet still considered risky?
Thanks for clarification!
It would be nice if a corresponding note were included in the release notes.
Cheers,
Alex
It would be nice if a corresponding note were included in the release notes.
Cheers,
Alex