https://bugzilla.wikimedia.org/show_bug.cgi?id=25340

Jeroen De Dauw <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
           Priority|Normal                      |High
             Status|NEW                         |ASSIGNED
                 CC|                            |[email protected],
                   |                            |[email protected]
                   |                            |rg
         AssignedTo|[email protected] |[email protected]
                   |rg                          |
           Severity|normal                      |major

--- Comment #1 from Jeroen De Dauw <[email protected]> 2010-09-29 
21:16:31 UTC ---
(In reply to comment #0)
> If you enter:
> 
> <script>alert("CSS Vulnerability");</script>
> 
> into the query window and click on the 'Find results' button, it will pop up 
> an
> alert window the the 'CSS Vulnerability' message.
> 
> This works on all versions of Media wiki and the semantic extensions I have
> tried.
> Works in both Firefox and IE.

Thanks for pointing this out. I will be fixing this today, and make a new SMW
release soon afterwards.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to