Closed (fixed)
Project:
Image Picker
Version:
6.x-1.2
Component:
Documentation
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
14 Jan 2009 at 09:49 UTC
Updated:
30 Jun 2009 at 20:40 UTC
Jump to comment: Most recent file
Comments
Comment #1
hutch commentedComment #2
heine commentedIs this fixed, won't fix, by design? When going through CVS I see this added:
making the relevant text:
IMO this isn't nearly strong enough as anyone with access to the Full HTML format can execute cross site scripting attacks (may lead to admin access).
Comment #3
heine commentedSetting status.
Comment #4
hutch commentedHeine, you are telling me what you don't want, not what you do want, please provide a patch ;-)
Comment #5
heine commentedComment #6
hutch commentedThanks for this patch, it will be in CVS shortly