[wp-trac] [WordPress Trac] #21523: Add additional escaping to credit.php

WordPress Trac wp-trac at lists.automattic.com
Thu Aug 9 01:13:41 UTC 2012


#21523: Add additional escaping to credit.php
--------------------------+-----------------------------
 Reporter:  Viper007Bond  |      Owner:
     Type:  enhancement   |     Status:  new
 Priority:  normal        |  Milestone:  Awaiting Review
Component:  Security      |    Version:  3.4.1
 Severity:  normal        |   Keywords:  has-patch
--------------------------+-----------------------------
 `/wp-admin/credits.php` doesn't fully escape all of the data that it
 displays. It should be properly escaped like any other third party data.

 What if WordPress.org were somehow compromised?

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/21523>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list