Install
Works with Drupal: 7.xUsing Composer to manage Drupal site dependencies
Downloads
Release notes
This release fixes a XSS vulnerability in the deploy_ui sub module caused by the module not sanitising output in the plan empty confirmation message. This vulnerability can only be exploited by users with the Administer Deployments permission and only impacts users with that permission who empty a plan created by a malicious user.
All changes since 7.x-2.0-beta1 release:
* #2692087: XSS vulnerability in empty plan functionality in deploy_ui.module by skwashd
* #2638954: Deleted node revisions should be removed from managed deploy plans by Cottser