Download & Extend

i18ntaxonomy concatenates variables to query string

Project:Internationalization
Version:6.x-1.x-dev
Component:Code
Category:bug report
Priority:normal
Assigned:Unassigned
Status:closed (fixed)

Issue Summary

Hi,

CivicActions is reviewing and upgrading multiple modules for use on client sites. Attached you will find a patch based on a review with the coder module. The i18ntaxonomy module contained a $variable in a sql query. While the data in this variable was perfectly safe and doesn't pose any security risk, it's not the correct way to do things and could pose a problem in the future if additional data is not handled correctly.

Cheers,
Stella

AttachmentSizeStatusTest resultOperations
i18ntaxonomy_sql.patch1.31 KBIgnored: Check issue status.NoneNone

Comments

#1

Status:needs review» fixed

Right, thanks

#2

Status:fixed» closed (fixed)

Automatically closed -- issue fixed for two weeks with no activity.

nobody click here