catalyst / totara-mod-ojt

https://github.com/catalyst/totara-mod-ojt/wiki
5 stars 21 forks source link

Force download of files attached to an OJT #24

Closed alexmorrisnz closed 4 years ago

alexmorrisnz commented 4 years ago

Thanks to Dan for the recommendation of the fix and Sergey for reporting. This forces downloading the files rather than viewing them thus moving the XSS issue from the site into the browsers sandbox/wherever they may open it. Fixes #23