16 Jul 2013

4images 1.7 – 1.7.11: Security fixes for XSS

We’ve been reported (thanks to jakovits) a cross site scripting vulnerability in 4images 1.7 – 1.7.11.

To fix this:

In global.php

find

and replace it with