MantisBT: master-1.2.x 9fc1dd81

Author Committer Branch Timestamp Parent
dhx dhx master-1.2.x 2010-08-05 04:00 master-1.2.x 243ff6f6
Affected Issues  0012238: XSS in print_all_bug_page_word.php when printing project and category names
Changeset

Fix 0012238: XSS in print_all_bug_page_word.php project/category names

print_all_bug_page_word.php does not correctly sanitise project and
category names. It is thus possible for a malicious user with project
manager access permissions (or higher) to redirect users to
print_all_bug_page_word.php to execute malicious JavaScript.

mod - print_all_bug_page_word.php Diff File