XSS can be exploited, but only from trusted users ("administer site configuration" permission).

Support from Acquia helps fund testing for Drupal Acquia logo

Comments

grisendo’s picture

I attach a patch

grisendo’s picture

Status: Active » Needs review
Dave Reid’s picture

Status: Needs review » Fixed

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.