Closed (fixed)
Project:
Exposed Filter Data
Version:
6.x-1.0
Component:
Code
Priority:
Critical
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
9 Feb 2011 at 04:23 UTC
Updated:
20 Jul 2026 at 22:05 UTC
Jump to comment: Most recent
Comments
Comment #1
joetsuihk commentedthe reason is, $view->exposed_input do not escape anything, any html tags inputed, see http://drupal.org/node/1053920
Comment #2
drummThis was fixed by https://www.drupal.org/forum/newsletters/security-advisories-for-contrib...
Please report potential security issues confidentially in the future.