[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#696999: unblock: mediawiki-extensions/2.11



On Sun, 2012-12-30 at 15:55 +0000, Jonathan Wiltshire wrote:
> Please unblock mediawiki-extensions to fix the security bug #696179 (no CVE
> has been assigned yet). This resolves an XSS attack on any user of a wiki
> importing a malicious RSS feed (insufficient escaping). 

Any idea what the comment in

++              array('a', /* does not work */ 'img')));

is about?

Regards,

Adam


Reply to: