Last modified: 2012-11-29 12:42:19 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T42523, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 40523 - Properly escape output
Properly escape output
Status: VERIFIED FIXED
Product: MediaWiki extensions
Classification: Unclassified
WikidataRepo (Other open bugs)
unspecified
All All
: Unprioritized normal (vote)
: ---
Assigned To: Wikidata bugs
:
Depends on:
Blocks: 40573
  Show dependency treegraph
 
Reported: 2012-09-26 10:03 UTC by jeblad
Modified: 2012-11-29 12:42 UTC (History)
2 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description jeblad 2012-09-26 10:03:50 UTC
Several places in the code values are passed on without being properly escaped by htmlspecialchars or similar.

Use this as a tracking bug for patchsets related to this problem.
Comment 1 jeblad 2012-09-26 10:44:59 UTC
repo/includes/actions/EditEntityAction.php
https://gerrit.wikimedia.org/r/#/c/25242/
Comment 2 jeblad 2012-09-26 10:47:42 UTC
repo/includes/special/SpecialCreateEntity.php
https://gerrit.wikimedia.org/r/25244
Comment 3 jeblad 2012-09-26 10:58:22 UTC
repo/includes/special/SpecialItemByTitle.php
https://gerrit.wikimedia.org/r/25246
Comment 4 jeblad 2012-09-26 11:23:00 UTC
repo/includes/ItemView.php
https://gerrit.wikimedia.org/r/25249
Comment 5 denny vrandecic 2012-09-26 12:08:56 UTC
repo/includes/special/SpecialItemDisambiguation.php
https://gerrit.wikimedia.org/r/#/c/25180/
Comment 6 Anja Jentzsch 2012-11-29 12:42:19 UTC
Verified in Wikidata demo time for sprint 17

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links