MantisBT: master-2.28 80990f43

Author Committer Branch Timestamp Parent
dregad dregad master-2.28 2026-03-15 20:23 master-2.28 5e6e52d9
Affected Issues  0036971: CVE-2026-33517: Stored HTML Injection / XSS in Tag Delete Confirmation via Unescaped Tag Name
Changeset

Properly escape tag name prior to display

Prevents XSS when displaying the confirmation message prior to deleting
a tag.

Fixes 0036971

mod - tag_delete.php Diff File