Post a reply

Write your message and submit

Click in the dark area of the image to send your post.

Go back

Topic review (newest first)

windracer
2025-10-24 14:41:50

Thanks for the clarification!

plg
2025-10-21 09:23:04

windracer wrote:

Will a similar fix be pushed for the v16 RC?

In addition to ddtddt answer, I'd like to add that the fix was applied first on "master" branch (from which we create RC  builds), then backported on branch 15.x (from which we create 15.x.x releases). We released 15.7.0 first because it is supposed to be "in production", as opposed to 16RC1 ;-)

ddtddt
2025-10-21 07:55:28

Hi :-)

windracer wrote:

Will a similar fix be pushed for the v16 RC?

RC is only for test

fix will be next RC

windracer
2025-10-21 00:21:04

Will a similar fix be pushed for the v16 RC?

plg
2025-10-20 18:56:50

We recently received a security report on Github by Takumi Katanoda concerning the possibility to target a Piwigo user to reset his/her password. We do not consider it as an "easy" attack but with his advice we have strengthen the security on the form to reset password. We have also made "less verbose" the reset password message to avoid revealing potentially interesting information to attackers, it was another security advisory reported by mateusz.stroba.

Thank you very much for your reports that help us to make Piwigo more secure.

https://sandbox.piwigo.com/i?/uploads/4/y/1/4y1zzhnrnw//2024/07/09/20240709141134-93118b73-la.jpg
Background image by Steve Johnson on Pexels

Piwigo 15.7.0 release note

Board footer

Powered by FluxBB

github linkedin newsletter Piwigo.org © 2002-2025 · Contact