Some panelizer admin pages utilize administrative names directly without additional sanitization. Luckily you need to be an admin to exploit this bug, so its not deserving of its own security issue. Its more of a general hardening task.

This was originally filed privately. We're moving it to the public queue after consultation with the security team.

CommentFileSizeAuthor
panelizer-sechardening-1.patch704 bytesjaperry

Comments

japerry created an issue.