Skip to content

Commit

Permalink
Update README.md
Browse files Browse the repository at this point in the history
  • Loading branch information
jeffersongoncalves authored May 23, 2018
1 parent b69f605 commit 048676d
Showing 1 changed file with 2 additions and 9 deletions.
11 changes: 2 additions & 9 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,12 +26,5 @@ Please see the [Documentation][doc], esp. the [Quick Start tutorial][quickstart]

This work is based on the [code by Frank Heider](https://github.com/fheider/cakephp-datatables).

___
## IMPORTANT SECURITY NOTICE for users prior to Oct 24, 2017

The original code by fheider is vulnerable to SQL injection attacks, which was made apparent by a recent
[addition to the CakePHP documentation](https://github.com/cakephp/cakephp/commit/b2b45af37f807068f6c23f152fe6e5bf64656915).
The vulnerability is fixed by a [breaking change](https://github.com/ypnos-web/cakephp-datatables/commit/81929ad62d1e4041d00c1904f67771fec04ecd5f)
in all branches in this repository. It affects the ordering and filtering functionality of DataTables in conjunction with
server-side processing. If you are using a prior version of this plugin, you need to update it immediately and, if needed, change your code to
[allow ordering and filtering with server-side processing](https://github.com/ypnos-web/cakephp-datatables/wiki/Quick-Start#enable-dynamic-filters-and-ordering).
This work is based on the [code by Johannes Jordan](https://github.com/ypnos-web/cakephp-datatables).

0 comments on commit 048676d

Please sign in to comment.