Ticket #1251 (closed defect (bug): fixed)

Opened 7 years ago

Last modified 5 years ago

XSS and HTML injection

Reported by: anonymousbugger Owned by: matt
Priority: normal Milestone: 2.1
Component: Security Version: 2.0.1
Severity: major Keywords: 2nd-opinion dev-feedback
Cc:

Change History

  • Patch set to No

comment:2   matt7 years ago

  • Owner changed from anonymous to matt
  • Status changed from new to closed
  • Resolution changed from 10 to 70
  • Status changed from closed to assigned
  • Resolution changed from 70 to 30

comment:5   ryan7 years ago

Debian maintainer contacted.

  • Keywords bg|2nd-opinion bg|dev-feedback added
  • Version set to 2.0.1

Are we going to address this? Maybe we should be filtering the title through KSES except for people with unfiltered_html capability.

comment:7   deko6 years ago

Is kses really the best solution? I've been using SafeHTML with WorpPress since my first wp 2.0 installation. I suggest SafeHTML be given consideration as a replacement for kses -  http://pixel-apes.com/safehtml/

  • Keywords 2nd-opinion dev-feedback added; bg|2nd-opinion bg|dev-feedback removed
  • Milestone set to 2.1
  • Status changed from assigned to closed
  • Resolution set to fixed

#2896 (and maybe others)

Note: See TracTickets for help on using tickets.