Brian Reilly
02/16/2024, 4:04 PMSebastiaan Naafs - van Dijk
02/20/2024, 11:12 AMSebastiaan Naafs - van Dijk
02/20/2024, 11:13 AMBrian Reilly
02/20/2024, 11:30 PMempty()
structGet()
and isDefined()
. I know #1 has been fixed in some Lucee 5.x versions, and #2 and #3 have been fixed in Lucee 6.0.1.59 (not certain about other versions). But if they're not "fixed" in Lucee 5.x, you can avoid them by disabling Client Management in Lucee admin (it should be off by default), and not passing using input to empty()
structGet()
and isDefined()
MasaCMS has a few instances of vulnerable isDefined()
calls, but they've been fixed as of Masa CMS 7.4.5