Commit graph

1555 commits

Author SHA1 Message Date
myvesta
7c9da855e8
Update secure_login.php 2021-08-29 14:05:15 +02:00
myvesta
8a5469abcd
Update secure_login.php 2021-08-29 12:39:48 +02:00
myvesta
834f939fbe
Exception for function prevent_get_csrf 2021-08-29 11:50:22 +02:00
myvesta
eae5c3418a
Preventing GET CSRFs 2021-08-29 11:14:11 +02:00
myvesta
49905063f6
Update secure_login.php 2021-08-29 11:09:24 +02:00
myvesta
085a25d165
Update secure_login.php 2021-08-29 01:59:49 +02:00
myvesta
59edb05f49
Proper way to fix CSRF in /edit/file/ 2021-08-29 01:20:12 +02:00
myvesta
11f1cfcf4e Proper way to fix CSRF in /schedule/backup/ 2021-08-29 00:54:57 +02:00
myvesta
0336e8b8d0
Preventing CSRF in /file_manager/fm_api.php 2021-08-29 00:14:15 +02:00
myvesta
9277b37800
Preventing CSRF in /schedule/backup 2021-08-29 00:12:09 +02:00
myvesta
92297f2fc2
Preventing CSRF in UploadHandler.php 2021-08-29 00:10:42 +02:00
myvesta
c2a30bcd31
Preventing CSRF in /edit/file/ 2021-08-29 00:07:41 +02:00
myvesta
c7bd10ab3b
Smarter preventing all POST CSRF 2021-08-29 00:04:27 +02:00
myvesta
0686c6d5f6
More logical check expression in secure_login.php 2021-08-28 23:35:10 +02:00
myvesta
43da9e2aa7
Preventing CSRF in file_manager/fm_api.php 2021-08-15 15:14:16 +02:00
myvesta
55c591535c
Preventing all CSRF 2021-08-15 14:53:16 +02:00
myvesta
1d73ff488b
Preventing CSRF in schedule / backup 2021-08-15 14:41:04 +02:00
myvesta
518e627b46
Update index.php 2021-08-15 14:37:53 +02:00
myvesta
9f55ef33cf
Update index.php 2021-08-15 14:36:45 +02:00
myvesta
d66afcbaaa
Preventing CSRF in schedule / backup 2021-08-15 14:20:13 +02:00
myvesta
d559763427
Preventing CSRF in edit/file 2021-08-15 14:15:48 +02:00
myvesta
914b53ea1c
Getting hostname from $_SERVER['HTTP_HOST'] for UploadHandler 2021-08-15 14:11:14 +02:00
myvesta
88596a8cd9
Fix for possible file inclusion vulnerability in i18n.php
Fix for https://github.com/serghey-rodin/vesta/issues/2052
2021-08-15 12:35:28 +02:00
myvesta
df11eaf33f Fix for "Broken or Risky Cryptographic Algorithm" 2021-08-14 22:36:07 +02:00
myvesta
cf75660818
Update list_backup_detail.html 2021-05-30 20:28:35 +02:00
myvesta
0233834da4
Update sr.php 2021-05-30 20:26:48 +02:00
myvesta
f1da73a7bd
Update list_backup_detail.html 2021-05-30 20:25:21 +02:00
myvesta
8fe06a2153
Update sr.php 2021-05-30 20:23:23 +02:00
myvesta
1739c8c731
Update list_backup_detail.html 2021-05-30 20:17:27 +02:00
myvesta
d368a7e6d4
More logical restore backup template 2021-05-30 19:21:06 +02:00
myvesta
543e6b5bc9
Sorting issue fix
Closing https://github.com/myvesta/vesta/issues/116
Thanks to @jaapmarcus and @hestiacp
2021-04-15 20:24:33 +02:00
myvesta
a4977253ca
css fix on right place
Thanks to Miloš Spasić
2021-03-23 14:33:27 +01:00
myvesta
c907e11151
rollback css fix 2021-03-23 14:11:45 +01:00
myvesta
1b9d3bb0cc
css fix 2021-03-17 13:21:14 +01:00
myvesta
c9b238a495
Ensure HTML will not be displayed in list log page 2021-03-14 23:22:33 +01:00
myvesta
3402071e95
Preventing uploads from other origin
Credits to:  Fady Othman, Security Consultant # ZINAD IT
2021-03-14 20:49:14 +01:00
myvesta
fdc6e191c2
Restrict v-make-tmp-file to tmp folder
Thanks to @hestiacp and @jaapmarcus
2021-03-14 19:09:10 +01:00
myvesta
81daa6413b
Checking period value in /list/rrd/ 2020-12-12 14:09:48 +01:00
myvesta
f31b4b4d41
Update index.php 2020-12-12 13:52:26 +01:00
myvesta
292d933f88
Preventing admin to do loginas action without token
This is useless issue and useless fix too.
2020-12-12 13:48:51 +01:00
myvesta
00b4267afd
htmlentities() for token 2020-12-12 13:43:27 +01:00
myvesta
5da09d9c5b
Fix for downloading backup of other users 2020-12-12 12:54:06 +01:00
myvesta
a48c92afb8
Merge pull request #95 from serghey-rodin/master
ACME fix from official Vesta repo
2020-10-25 02:23:20 +02:00
myvesta
d6eb5f0ba7
Disabling login with 'root'
tnx @jaapmarcus and HestiaCP
2020-08-30 00:10:04 +02:00
myrevery
ce5d209c13
Update cn.php 2020-08-25 14:58:01 -07:00
myvesta
1320f14c16
Better place for changelog link 2020-08-17 14:51:55 +02:00
myvesta
c7a3f7c414
Update list_user.html 2020-07-26 01:33:30 +02:00
myvesta
6159b9f3b1
Create favicon.ico 2020-07-25 01:30:37 +02:00
myvesta
afa77ffa5d
Delete favicon.ico 2020-07-25 01:29:34 +02:00
myvesta
a9b48b4594
Changing Vesta to myVesta in title of hosting panel pages 2020-07-21 00:35:12 +02:00