From 1751057dec48afac715630aa162a2671615219c8 Mon Sep 17 00:00:00 2001 From: Manuele Maporti <87815893+mapokid@users.noreply.github.com> Date: Thu, 20 Oct 2022 11:00:24 +0200 Subject: [PATCH] Add files via upload TT-261314: NEW updated GrapesJs plugin TT-261010: FIX SEC weak password reset token, RCE TT-261010: FIX SEC file upload --- .../modules/SDK/src/Grapes/GrapesBody.tpl | 4 +- .../modules/SDK/src/Grapes/GrapesHeader.tpl | 6 +- .../modules/SDK/src/Grapes/GrapesPage.tpl | 11 +- config.template.php | 4 +- .../connectors/php/filemanager.class.php | 5 + include/js/grapesjs/css/grapes.min.css | 2 +- include/js/grapesjs/grapes.min.js | 13 +- include/js/grapesjs/grapes.min.js.map | 2 +- .../js/grapesjs/grapesjs-image-manager.min.js | 4 +- .../grapesjs-image-manager.min.js.map | 1 + .../grapesjs/grapesjs-plugin-ckeditor.min.js | 4 +- modules/SDK/src/Grapes/Grapes.js | 69 +++- modules/Update/changes/2211_2212.php | 43 ++ modules/Update/changes/2212_2213.php | 12 + modules/Users/Authenticate.php | 11 +- modules/Users/RecoverPwd.php | 373 ++++++++++++------ modules/Users/Users.php | 12 + modules/Users/language/en_us.lang.php | 8 +- modules/Users/language/it_it.lang.php | 8 +- vteversion.php | 6 +- vtlib/ModuleDir/20.04.2/DetailViewAjax.php | 43 ++ vtlib/ModuleDir/20.04.2/EditView.php | 19 + vtlib/ModuleDir/20.04.2/ModuleFile.js | 16 + vtlib/ModuleDir/20.04.2/ModuleFile.php | 232 +++++++++++ vtlib/ModuleDir/20.04.2/ModuleFileAjax.php | 6 + vtlib/ModuleDir/20.04.2/Save.php | 64 +++ .../ModuleDir/20.04.2/language/en_us.lang.php | 16 + .../ModuleDir/20.04.2/language/it_it.lang.php | 16 + 28 files changed, 837 insertions(+), 173 deletions(-) create mode 100644 include/js/grapesjs/grapesjs-image-manager.min.js.map create mode 100644 modules/Update/changes/2211_2212.php create mode 100644 modules/Update/changes/2212_2213.php create mode 100644 vtlib/ModuleDir/20.04.2/DetailViewAjax.php create mode 100644 vtlib/ModuleDir/20.04.2/EditView.php create mode 100644 vtlib/ModuleDir/20.04.2/ModuleFile.js create mode 100644 vtlib/ModuleDir/20.04.2/ModuleFile.php create mode 100644 vtlib/ModuleDir/20.04.2/ModuleFileAjax.php create mode 100644 vtlib/ModuleDir/20.04.2/Save.php create mode 100644 vtlib/ModuleDir/20.04.2/language/en_us.lang.php create mode 100644 vtlib/ModuleDir/20.04.2/language/it_it.lang.php diff --git a/Smarty/templates/modules/SDK/src/Grapes/GrapesBody.tpl b/Smarty/templates/modules/SDK/src/Grapes/GrapesBody.tpl index 9caaf50..5d8ab37 100644 --- a/Smarty/templates/modules/SDK/src/Grapes/GrapesBody.tpl +++ b/Smarty/templates/modules/SDK/src/Grapes/GrapesBody.tpl @@ -22,7 +22,7 @@ - +{* crmv@231245 *} \ No newline at end of file + diff --git a/Smarty/templates/modules/SDK/src/Grapes/GrapesHeader.tpl b/Smarty/templates/modules/SDK/src/Grapes/GrapesHeader.tpl index 6007f86..3f1c749 100644 --- a/Smarty/templates/modules/SDK/src/Grapes/GrapesHeader.tpl +++ b/Smarty/templates/modules/SDK/src/Grapes/GrapesHeader.tpl @@ -13,9 +13,9 @@ - + {* crmv@231245 *} - + {* crmv@231245 *}