Some panelizer admin pages utilize administrative names directly without additional sanitization. Luckily you need to be an admin to exploit this bug, so its not deserving of its own security issue. Its more of a general hardening task.
This was originally filed privately. We're moving it to the public queue after consultation with the security team.
| Comment | File | Size | Author |
|---|---|---|---|
| panelizer-sechardening-1.patch | 704 bytes | japerry |
Comments