[Bug 64183] JS injection vulnerability in Html::element()?

2014-06-30 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=64183 Chris Steipp changed: What|Removed |Added Group|security| Component|Core

[Bug 64183] JS injection vulnerability in Html::element()?

2014-04-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=64183 --- Comment #2 from Yaron Koren --- We discussed it in the comments here: https://gerrit.wikimedia.org/r/#/c/124995/ But based on what you're saying, it sounds like there was just a misunderstanding about escaping vs. mangling of Javascript c

[Bug 64183] JS injection vulnerability in Html::element()?

2014-04-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=64183 --- Comment #1 from Bartosz DziewoƄski --- (In reply to Yaron Koren from comment #0) I'm told that > this is not correct behavior, so I'm submitting a bug for it. By whom? While it might not be the most fortunate behavior, Html::element only