Ticket #1871 (closed defect (bug): invalid)

Opened 6 years ago

Last modified 2 years ago

Redacted

Reported by: anonymous Owned by: anonymous
Priority: high Milestone:
Component: Security Version: 1.5.2
Severity: normal Keywords:
Cc:

Description (last modified by markjaquith) (diff)

Redacted

Change History

Standard policy is to email security threats to security@…, so that the problem can be tested and acted on as quickly as possible, with the minimum number of people possible getting access to the threat.

Seems to me that it would be better to have the urlencode() protection within the wp_redirect() function itself...

  • Status changed from new to closed
  • Summary changed from XSS vulnerability through redirects to Redacted
  • Resolution set to invalid
  • Description modified (diff)
  • Reporter ManiacSoftwareManiacsOrg deleted

Let's not give the bad guys a head start. Information has been saved and forwarded to security@…

Note: See TracTickets for help on using tickets.