User supplied arguments for regex must be passed through preg_quote(). Patch attached.

This issue does not need to pass through the regular security process because there isn't a full release yet. Simply commit this patch and mark the next release as a security update.

CommentFileSizeAuthor
smart_paging_security.diff1.96 KBdalin

Comments

arpeggio’s picture

Status: Needs review » Fixed

Thank you for reporting the bug and the patch. I have already committed and pushed the patch.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.