From 066c9bf6e14cf2e6ec57d4bc7354aee38a08a944 Mon Sep 17 00:00:00 2001 From: Frederic Guillot Date: Wed, 16 Aug 2017 20:46:47 -0700 Subject: Add CVE ID to ChangeLog --- ChangeLog | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'ChangeLog') diff --git a/ChangeLog b/ChangeLog index c889556b..485814e5 100644 --- a/ChangeLog +++ b/ChangeLog @@ -4,7 +4,8 @@ Version 1.0.46 (August 13, 2017) Security Issues: * Fix two privilege escalation issues: a standard user could reset the password -of another user by altering form data. +of another user (including admin) by altering form data. +(CVE-2017-12850 and CVE-2017-12851, discovered by "chbi"). Improvements: -- cgit v1.2.3