MantisBT: master-2.28 9e43cd80

Author Committer Branch Timestamp Parent
dregad dregad master-2.28 2026-05-07 11:30 master-2.28 26647b2e
Affected Issues  0037020: CVE-2026-44657: Stored XSS in File Download
Changeset

Purge file_show_inline security token after use

This ensures that the token cannot be reused after displaying the
attachment inline.

Issue 0037020

mod - file_download.php Diff File