[wp-trac] [WordPress Trac] #22861: Wordpress 3.5 - Cross Site Scripting Vulnerability

WordPress Trac noreply at wordpress.org
Tue Dec 11 21:26:38 UTC 2012


#22861: Wordpress 3.5 - Cross Site Scripting Vulnerability
-----------------------------+----------------------
 Reporter:  shubhammittal01  |       Owner:
     Type:  defect (bug)     |      Status:  closed
 Priority:  normal           |   Milestone:
Component:  Security         |     Version:
 Severity:  normal           |  Resolution:  invalid
 Keywords:                   |
-----------------------------+----------------------
Changes (by helenyhou):

 * component:  General => Security


Comment:

 See:
 http://codex.wordpress.org/FAQ_Security#Why_are_some_users_allowed_to_post_unfiltered_HTML.3F.

 Also, when creating this ticket, this appeared at the top of the form:
 > Do not report potential security vulnerabilities here. Read the
 [http://codex.wordpress.org/FAQ_Security Security FAQ] and email us at
 security at wordpress .org.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/22861#comment:3>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list