Inspecting $_POST on confirmations may lead to CSRF vulnerabilities: one should use a submit handler. This patch went into 5.x as well.

CommentFileSizeAuthor
#2 confirm_form_doc.patch908 bytesheine
6_confirm_form.patch620 bytesheine

Comments

heine’s picture

patch was by barry jaspan btw.

heine’s picture

StatusFileSize
new908 bytes

Instead of making a mistery of what file changed, a patch with complete headers.

gábor hojtsy’s picture

Status: Needs review » Fixed

Committed, thanks.

Anonymous’s picture

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for two weeks with no activity.