Security Advisories (5)
CVE-2021-23562 (2021-12-03)

This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.

CVE-2021-41182 (2021-10-26)

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.

CVE-2021-41183 (2021-10-26)

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.

CVE-2021-41184 (2021-10-26)

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.

CVE-2016-4566 (2016-05-22)

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

NAME

Yukki::User - Encapsulates Yukki users

VERSION

version 0.991_005

SYNOPSIS

use Yukki::User;

my $user_file = $app->locate('user_path', 'bob');
my $user = Yukki::User->load_yaml($user_file);

say "login name: ", $user->login_name;
say "password: ", $user->password;
say "name: ", $user->name;
say "email: ", $user->email;
say "groups: ", join(', ', $user->groups->@*);

DESCRIPTION

Encapsulates the definition of a user object. Users are defined to provide information about the author of each change in the wiki.

ROLES

Yukki::Role::Savable

ATTRIBUTES

login_name

This is the name the user uses to login.

password

This is the hashed password for the user.

name

This is the full name of the user, used as the author name on commits.

email

This is the email address of the user, used to uniquely identify the author in commits.

groups

This is the list of groups to which the user belongs.

METHODS

groups_string

Returns the groups concatenated together into a single string.

savable_attributes

Returns the savable attributes.

AUTHOR

Andrew Sterling Hanenkamp <hanenkamp@cpan.org>

COPYRIGHT AND LICENSE

This software is copyright (c) 2017 by Qubling Software LLC.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.