diff --git a/CHANGELOG b/CHANGELOG index c2aa733b7..c0019bb16 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -23,7 +23,7 @@ CHANGELOG Roundcube Webmail - Managesieve: Fix parser issue with empty lines between comments (#5657) - Managesieve: Fix possible defect in handling \r\n in scripts (#5685) - Fix/rephrase "unsaved changes" warning when cancelling a draft (#5610) -- Fix XSS issue in handling of a style tag inside of an svg element +- Fix XSS issue in handling of a style tag inside of an svg element [CVE-2017-6820] - Fix bug where settings/upload.inc could not be used by plugins (#5694) RELEASE 1.3-beta