Make WordPress Core

Opened 21 years ago

Closed 20 years ago

#1251 closed defect (bug) (fixed)

XSS and HTML injection

Reported by: anonymousbugger Owned by: matt
Priority: normal Milestone: 2.1
Component: Security Version: 2.0.1
Severity: major Keywords: 2nd-opinion dev-feedback
Cc: Focuses:

Description

Change History (9)

#1 @anonymousbugger
21 years ago

  • PatchNo

#2 @matt
21 years ago

  • Owner changed from anonymous to matt
  • Resolution 1070
  • Status newclosed

#3 @anonymousbugger
21 years ago

  • Resolution 7030
  • Status closedassigned

#5 @ryan
21 years ago

Debian maintainer contacted.

#6 @markjaquith
21 years ago

  • Keywords bg|2nd-opinion bg|dev-feedback added
  • Version2.0.1

Are we going to address this? Maybe we should be filtering the title through KSES except for people with unfiltered_html capability.

#7 @deko
20 years ago

Is kses really the best solution? I've been using SafeHTML with WorpPress since my first wp 2.0 installation. I suggest SafeHTML be given consideration as a replacement for kses - http://pixel-apes.com/safehtml/

#8 @Nazgul
20 years ago

  • Keywords 2nd-opinion dev-feedback added; bg|2nd-opinion bg|dev-feedback removed
  • Milestone2.1

#9 @markjaquith
20 years ago

  • Resolutionfixed
  • Status assignedclosed

#2896 (and maybe others)

Note: See TracTickets for help on using tickets.