You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When the admin interface is used to set the config setting error.display, it is impossible to set it to -1 (System error). The yaml file after saving looks like this:
This is an information disclosure security vulnerability, because Grav falls back to the full backtrace(!) when the user presumably wanted to make sure to leak as little information as possible.
The text was updated successfully, but these errors were encountered:
When the admin interface is used to set the config setting
error.display
, it is impossible to set it to-1 (System error)
. The yaml file after saving looks like this:Note that display is set to the string
-1
due to the quotes. Grav later checks the setting usingis_int
and then discards the value.This is an information disclosure security vulnerability, because Grav falls back to the full backtrace(!) when the user presumably wanted to make sure to leak as little information as possible.
The text was updated successfully, but these errors were encountered: