Actions
Bug #2385
closednot htmlescaped inputs
Bug #2385:
not htmlescaped inputs
Description
Updated by beat over 15 years ago
admin.cbgroupjive.html.php has many unescaped outputs, giving potential injections: e.g.:
could be safer as (admitting that $editJs is safe::
Updated by krileon over 15 years ago
- Status changed from New to Resolved
- Assignee changed from krileon to beat
- % Done changed from 0 to 100
Fixed with r1607
Updated by krileon over 15 years ago
- Status changed from Resolved to Closed
Actions