Closed (fixed)
Project:
Project issue file test
Version:
5.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
10 Nov 2008 at 02:25 UTC
Updated:
24 Nov 2008 at 20:12 UTC
The links displayed in the tests results to re-test a patch pose an XSS vulnerability.
Talked with hunmonk and he agreed and is willing to review patches. :)
Since links currently display to all authenticated users and only mark a patch for re-testing this doesn't pose a major threat, but a good habit to get into.
Comments
Comment #1
hunmonk commentedhttp://drupal.org/cvs?commit=152194
deployed on p.d.o and d.o