cfUniForm v4.6.0 - IMPORTANT PrettyComments XSS Vulnerability Fix Release
Posted on September 11, 2011 at 5:38 PM in ColdFusion, Uni-Form Tag Library, jQuery
IMPORTANT: If you have textareas in any of your forms, you will want to upgrade!
A big THANK YOU! to Marc Esher for identifying an XSS vulnerability with the plugin that cfUniForm had previously used for "expandable" textareas. Marc contacted the author of the PrettyComments jQuery plugin repeatedly in an effort to help the author resolve this issue. However, the author gave no indication that he was interested in a fix. Because of this, cfUniForm now uses Elastic for expandable textareas.


