Opened 8 years ago

Closed 8 years ago

Last modified 4 years ago

#1871 closed defect (bug) (invalid)

Redacted

Reported by: anonymous Owned by: anonymous
Priority: high Milestone:
Component: Security Version: 1.5.2
Severity: normal Keywords:
Cc:

Change History (4)

Standard policy is to email security threats to security@…, so that the problem can be tested and acted on as quickly as possible, with the minimum number of people possible getting access to the threat.

Seems to me that it would be better to have the urlencode() protection within the wp_redirect() function itself...

  • Description modified (diff)
  • Reporter ManiacSoftwareManiacsOrg deleted
  • Resolution set to invalid
  • Status changed from new to closed
  • Summary changed from XSS vulnerability through redirects to Redacted

Let's not give the bad guys a head start. Information has been saved and forwarded to security@…

Note: See TracTickets for help on using tickets.