Closed (fixed)
Project:
Czech audit
Version:
5.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Reporter:
Created:
31 Jan 2008 at 19:48 UTC
Updated:
15 Feb 2008 at 00:21 UTC
Hi/Ahoj :-)
User submitted strings (which role name definitely is) should never be passed to t(). I also added check_plain() to it. It's not a security threat/bug, because roles are always created by administrator, but let's do this the right way and be sure.
Attaching a patch. I also fixed one english typo and removed $role_varname, as you never used it.
--
Jakub Suchy
| Comment | File | Size | Author |
|---|---|---|---|
| czech_audit_role.patch | 1.39 KB | meba |
Comments
Comment #1
michal.cihar commentedComment #2
Anonymous (not verified) commentedAutomatically closed -- issue fixed for two weeks with no activity.