Opened 8 years ago

Closed 7 years ago

#1251 closed defect (bug) (fixed)

XSS and HTML injection

Reported by: anonymousbugger Owned by: matt
Priority: normal Milestone: 2.1
Component: Security Version: 2.0.1
Severity: major Keywords: 2nd-opinion dev-feedback
Cc:

Change History (9)

  • Patch set to No

comment:2   matt8 years ago

  • Owner changed from anonymous to matt
  • Resolution changed from 10 to 70
  • Status changed from new to closed
  • Resolution changed from 70 to 30
  • Status changed from closed to assigned

comment:5   ryan8 years ago

Debian maintainer contacted.

  • Keywords bg|2nd-opinion bg|dev-feedback added
  • Version set to 2.0.1

Are we going to address this? Maybe we should be filtering the title through KSES except for people with unfiltered_html capability.

comment:7   deko7 years ago

Is kses really the best solution? I've been using SafeHTML with WorpPress since my first wp 2.0 installation. I suggest SafeHTML be given consideration as a replacement for kses - http://pixel-apes.com/safehtml/

  • Keywords 2nd-opinion dev-feedback added; bg|2nd-opinion bg|dev-feedback removed
  • Milestone set to 2.1
  • Resolution set to fixed
  • Status changed from assigned to closed

#2896 (and maybe others)

Note: See TracTickets for help on using tickets.