SA-CONTRIB-2014-003 - Doubleclick for Publishers DFP - Cross Site Scripting (XSS)
This releases addresses a security permission issue from PSA-2014-001.
Changes since 7.x-1.3:
See SA-CONTRIB-2014-001.
Changes since 7.x-1.2:
SA-CONTRIB-2013-098 - Ubercart - Session Fixation Vulnerability
Changes since 7.x-3.5:
Changes since 6.x-2.12:
The security issue is caused by a mishandling of boolean access callbacks when OG Features overrides all menu items. Boolean access callbacks in menu items that are explicitly set to FALSE will be open for access.