Leaving institution and set password email not escaped for HTML

Bug #802347 reported by Hugh Davenport
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
Fix Released
Low
Hugh Davenport

Bug Description

The email sent when a user leaves an institution and needs to set a password is not escaped.

Revision history for this message
Hugh Davenport (hugh-davenport) wrote :
Revision history for this message
François Marier (fmarier) wrote :

I don't think that this is a security problem, however, if it were, it shouldn't be submitted to gerrit because that makes the vulnerability public :)

security vulnerability: yes → no
visibility: private → public
Changed in mahara:
status: In Progress → Fix Committed
milestone: none → 1.5.0
Melissa Draper (melissa)
Changed in mahara:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.