Action labels are not always properly escaped. Sometimes twice, sometimes not at all.

CommentFileSizeAuthor
actions-double-escaping-d7.patch3.44 KBheine

Comments

gábor hojtsy’s picture

BTW this is a followup to SA-CORE-2010-002.

drunken monkey’s picture

Status: Needs review » Reviewed & tested by the community

Looks good to me.

dries’s picture

Status: Reviewed & tested by the community » Fixed

Yay! Committed to CVS HEAD.

Status: Fixed » Closed (fixed)
Issue tags: -Security Advisory follow-up

Automatically closed -- issue fixed for 2 weeks with no activity.