dolibarr/htdocs
Laurent Destailleur 736b11913d Debug v24
2026-08-12 22:40:57 +02:00
..
accountancy Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
adherents css 2026-08-12 21:37:26 +02:00
admin Revert "/imports/index.php wrongly shows access refused (#39379)" (#39386) 2026-08-04 22:23:57 +02:00
ai Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
api Fixed removed property pass_indatabase_crypted in api result - reported 2026-08-09 19:49:05 +02:00
asset Qual: Fix 'SqlInjection' notices (#39229) 2026-07-20 15:26:43 +02:00
asterisk
barcode
blockedlog Revert "/imports/index.php wrongly shows access refused (#39379)" (#39386) 2026-08-04 22:23:57 +02:00
bom Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
bookcal Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
bookmarks Qual: Fix 'SqlInjection' notices (#39223) 2026-07-20 02:51:42 +02:00
categories Qual: Fix 'SqlInjection' notices (#39213) 2026-07-19 17:32:14 +02:00
collab
comm Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
commande Merge branch '24.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:42 +02:00
compta Fix #37599 make addline() honor the same credit note sign gate as updateline() (#39455) 2026-08-11 19:46:59 +02:00
conf
contact Fix old image not deleted 2026-08-07 18:27:23 +02:00
contrat Debug v24 2026-08-12 22:40:57 +02:00
core Debug v24 2026-08-12 22:40:57 +02:00
cron Qual: Fix 'SqlInjection' notices (#39221) 2026-07-20 02:51:11 +02:00
custom
datapolicy Qual: Fix 'SqlInjection' notices (#39213) 2026-07-19 17:32:14 +02:00
dav Revert "/imports/index.php wrongly shows access refused (#39379)" (#39386) 2026-08-04 22:23:57 +02:00
debugbar
delivery Qual: Fix 'SqlInjection' notices (#39219) 2026-07-20 02:50:44 +02:00
don Qual: Fix 'SqlInjection' notices (#39225) 2026-07-20 02:52:07 +02:00
ecm fix: Replace db->escape with db->sanitize in SQL query construction (#39357) 2026-08-04 18:40:04 +02:00
emailcollector Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
eventorganization fix: Replace db->escape with db->sanitize in SQL query construction (#39357) 2026-08-04 18:40:04 +02:00
expedition Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
expensereport Fix must exclude some properties in post/put of expensereport api - 2026-08-09 19:59:33 +02:00
exports Fix deletion must not use the glob by default. 2026-07-29 13:20:28 +02:00
fichinter Qual: Fix 'SqlInjection' notices (#39216) 2026-07-23 19:06:39 +02:00
fourn Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
ftp Qual: Fix french comments and improve detector (#39026) 2026-07-01 12:26:51 +02:00
holiday Qual: Fix 'SqlInjection' notices (#39232) 2026-08-01 23:54:52 +02:00
hrm Fix deletion must not use the glob by default. 2026-07-29 13:20:28 +02:00
imports Redo #39379 2026-08-04 22:46:09 +02:00
includes Automated merge from 23.0 to develop 2026-07-15 02:06:09 +02:00
install Clean bad merge 2026-08-05 23:21:48 +02:00
intracommreport Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
knowledgemanagement fix: Replace db->escape with db->sanitize in SQL query construction (#39357) 2026-08-04 18:40:04 +02:00
langs Revert "/imports/index.php wrongly shows access refused (#39379)" (#39386) 2026-08-04 22:23:57 +02:00
loan Qual: Fix 'SqlInjection' notices (#39225) 2026-07-20 02:52:07 +02:00
mailmanspip/class
margin Qual: Update SQL query variables for situation mode in margin reports (#39282) 2026-07-27 13:02:34 +02:00
modulebuilder Revert "/imports/index.php wrongly shows access refused (#39379)" (#39386) 2026-08-04 22:23:57 +02:00
mrp Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
multicurrency Qual: Fix phan notices (#39354) 2026-08-04 16:40:20 +02:00
opensurvey Qual: Fix 'SqlInjection' notices (#39223) 2026-07-20 02:51:42 +02:00
partnership fix: Replace db->escape with db->sanitize in SQL query construction (#39357) 2026-08-04 18:40:04 +02:00
paypal FIX: PayPal API calls set CURLOPT_SSL_VERIFYHOST to a bool instead of 2 (#39155) 2026-07-16 02:23:26 +02:00
printing avoid warnings in admin printing 2026-06-24 17:52:04 +02:00
product QUAL: Add SqlInjectionPlugin to detect unsafe SQL variable usage (fixes, notices) (#38722) 2026-08-08 11:19:04 +02:00
projet Debug v24 - Switch contact status 2026-08-07 19:43:34 +02:00
public Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
quickmemo FIX : Require write permission and check owner for unarchive memo (#39344) 2026-07-31 19:04:39 +02:00
reception Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
recruitment Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
resource Qual: Fix 'SqlInjection' notices (#39223) 2026-07-20 02:51:42 +02:00
salaries Qual: Remove unnecessary quotes around integer values in SQL queries (#39290) 2026-07-27 12:59:14 +02:00
societe Revert "/imports/index.php wrongly shows access refused (#39379)" (#39386) 2026-08-04 22:23:57 +02:00
stripe
subtotals
supplier_invoice/admin clean code for action specimen (#38865) 2026-06-25 19:01:16 +02:00
supplier_order/admin
supplier_proposal Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
takepos Qual: Fix 'SqlInjection' notices (#39232) 2026-08-01 23:54:52 +02:00
theme Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
ticket Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
user Qual: Remove unused use statement in api_users.class.php that breaks phan CI (#39443) 2026-08-11 02:22:55 +02:00
variants Qual: Fix 'SqlInjection' notices (#39223) 2026-07-20 02:51:42 +02:00
webhook Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
webportal Qual: Fix 'SqlInjection' notices (#39232) 2026-08-01 23:54:52 +02:00
webservices Qual: Fix 'SqlInjection' notices (#39229) 2026-07-20 15:26:43 +02:00
website Fix a user without perm for dyn content can import dyn templates - 2026-08-06 19:07:48 +02:00
workstation Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
zapier
document.php Fix file access with hasp parameter - reported by tremor hunter 2026-08-12 22:10:23 +02:00
favicon.ico
filefunc.inc.php Move file securitycore.lib.php into blockedlog directory. 2026-06-19 22:07:57 +02:00
index.php
main.inc.php Clean code 2026-08-07 19:00:27 +02:00
master.inc.php
robots.txt
security.txt
version.inc.php Prepare 24.0 release 2026-08-12 22:04:04 +02:00
viewimage.php Fix file access with hasp parameter - reported by tremor hunter 2026-08-12 22:10:23 +02:00
waf.inc.php Fix: more complete blacklist in waf - reported by Paweł Bednarz 2026-08-09 02:01:05 +02:00