Ticket #3937 (closed defect: fixed)
Opened 1 year ago
Last modified 1 year ago
All browser-bound outputs of add_query_arg() or remove_query_arg() must be sanitized with attribute_escape()
| Reported by: | markjaquith | Assigned to: | anonymous |
|---|---|---|---|
| Priority: | highest omg bbq | Milestone: | 2.0.10 |
| Component: | Security | Version: | 2.2 |
| Severity: | critical | Keywords: | security |
| Cc: |
