Inspecting $_POST on confirmations may lead to CSRF vulnerabilities: one should use a submit handler. This patch went into 5.x as well.
| Comment | File | Size | Author |
|---|---|---|---|
| #2 | confirm_form_doc.patch | 908 bytes | heine |
| 6_confirm_form.patch | 620 bytes | heine |
Inspecting $_POST on confirmations may lead to CSRF vulnerabilities: one should use a submit handler. This patch went into 5.x as well.
| Comment | File | Size | Author |
|---|---|---|---|
| #2 | confirm_form_doc.patch | 908 bytes | heine |
| 6_confirm_form.patch | 620 bytes | heine |
Comments
Comment #1
heine commentedpatch was by barry jaspan btw.
Comment #2
heine commentedInstead of making a mistery of what file changed, a patch with complete headers.
Comment #3
gábor hojtsyCommitted, thanks.
Comment #4
(not verified) commentedAutomatically closed -- issue fixed for two weeks with no activity.