Here's the patch for D7 from the security team, to prevent someone from redirecting someone to evilhacker.com on login destination. Stock D6 is not vulnerable, but doesn't hurt to harden this up. Tagging accordingly.

Commit credit should go to chx, fago, greggles

Private tracker: #61499

Support from Acquia helps fund testing for Drupal Acquia logo

Comments

Berdir’s picture

Status: Active » Needs review
FileSize
1.57 KB
973 bytes

Re-rolled.

aspilicious’s picture

Status: Needs review » Reviewed & tested by the community

Identical! :D

ciriticals--

webchick’s picture

Status: Reviewed & tested by the community » Fixed

Excellent, thank you!

Committed and pushed to 8.x.

Automatically closed -- issue fixed for 2 weeks with no activity.

Anonymous’s picture

Issue summary: View changes

x