[Bug 64183] JS injection vulnerability in Html::element()?

2014-06-30 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=64183 Chris Steipp cste...@wikimedia.org changed: What|Removed |Added Group|security|

[Bug 64183] JS injection vulnerability in Html::element()?

2014-04-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=64183 --- Comment #1 from Bartosz DziewoƄski matma@gmail.com --- (In reply to Yaron Koren from comment #0) I'm told that this is not correct behavior, so I'm submitting a bug for it. By whom? While it might not be the most fortunate behavior,

[Bug 64183] JS injection vulnerability in Html::element()?

2014-04-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=64183 --- Comment #2 from Yaron Koren yaro...@gmail.com --- We discussed it in the comments here: https://gerrit.wikimedia.org/r/#/c/124995/ But based on what you're saying, it sounds like there was just a misunderstanding about escaping vs.