Hi/Ahoj :-)

User submitted strings (which role name definitely is) should never be passed to t(). I also added check_plain() to it. It's not a security threat/bug, because roles are always created by administrator, but let's do this the right way and be sure.

Attaching a patch. I also fixed one english typo and removed $role_varname, as you never used it.

--
Jakub Suchy

CommentFileSizeAuthor
czech_audit_role.patch1.39 KBmeba

Comments

michal.cihar’s picture

Assigned: Unassigned » michal.cihar
Status: Needs review » Fixed
Anonymous’s picture

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for two weeks with no activity.