#8315 XSS when adding another user to a project

v1.11.1
closed
nobody
None
General
nobody
2019-07-16
2019-07-10
No

When adding a user to a project, the user's display name is not escaped.

Discussion

  • Dave Brondsema

    Dave Brondsema - 2019-07-10
    • status: open --> review
     
  • Dave Brondsema

    Dave Brondsema - 2019-07-10

    Fixed on db/8315

     
  • Kenton Taylor

    Kenton Taylor - 2019-07-10
    • status: review --> closed
     
  • Dave Brondsema

    Dave Brondsema - 2019-07-15
    • Milestone: unreleased --> v1.11.1
     
  • Dave Brondsema

    Dave Brondsema - 2019-07-16
    • private: Yes --> No
     

Log in to post a comment.