Thomas Gerbet (tgerbet)2017-05-30 09:05 Adding planned disclosure date. Issue has been fixed in PHPWiki by the maintainer, see revision 10007 in the PHPWiki source code repo on Sourceforge.
Thomas Gerbet (tgerbet)2017-05-18 14:50 Marc-Etienne Vargenau has acknowledged the initial contact, full vulnerability details has been transmitted.
Nicolas Terray (nterray)2017-05-17 16:36 gerrit #8407 integrated into Tuleap 9.7.99.98 Status changed from Under review to ClosedConnected artifacts Added Fixed in: rel #10116Close date set to 2017-05-17
Thomas Gerbet (tgerbet)2017-05-17 15:05 For information, the vulnerability is also present upstream. No way to report security issues is given on the Sourceforge project pages [1], I have tried to reach out directly to Marc-Etienne Vargenau which seem to be the last active maintainer. Waiting for a response. [1] https://sourceforge.net/projects/phpwiki/
Thomas Gerbet (tgerbet)2017-05-16 16:50 A patch is under review: gerrit #8407. Status changed from Under implementation to Under review