Modify ↓
Opened 14 years ago
Closed 14 years ago
#8580 closed defect (fixed)
Comments not properly escaped / script injection possibility
Reported by: | anonymous | Owned by: | Richard Liao |
---|---|---|---|
Priority: | normal | Component: | TracTicketChangelogPlugin |
Severity: | major | Keywords: | |
Cc: | Trac Release: | 0.12 |
Description
The ChangeLog comment on the ticket view is not escaped which, in addition to not showing "<text>" style comments, means it is possible to inject script tags.
Attachments (0)
Note: See
TracTickets for help on using
tickets.
(In [9935]) Fixed #8580