[Tickets #2830] No validation of data in function getFormData resulit in XSS vulnerability
bugs@bugs.horde.org
bugs at bugs.horde.org
Thu Oct 27 00:21:37 PDT 2005
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.
Ticket URL: http://bugs.horde.org/ticket/?id=2830
-----------------------------------------------------------------------
Ticket | 2830
Updated By | Jan Schneider <jan at horde.org>
Summary | No validation of data in function getFormData resulit in XSS vulnerability
Queue | Horde Base
Version | 2.2.8
-State | Unconfirmed
+State | Assigned
Priority | 2. Medium
Type | Bug
-Owners |
+Owners | Horde Developers
-----------------------------------------------------------------------
Jan Schneider <jan at horde.org> (2005-10-27 00:21) wrote:
Just to give an update: This is not being ignored, we just had to discuss
first if we are still going to support Horde 2.
We will, until Horde 3.1 is released, so expect a fix being released soon.
More information about the bugs
mailing list