Last modified: 2014-02-12 23:32:52 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T45534, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 43534 - Don't parse username in Special:PasswordReset
Don't parse username in Special:PasswordReset
Status: NEW
Product: MediaWiki
Classification: Unclassified
Special pages (Other open bugs)
1.20.x
All All
: Normal normal (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-12-31 11:18 UTC by touprouc
Modified: 2014-02-12 23:32 UTC (History)
3 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description touprouc 2012-12-31 11:18:35 UTC
http://www.mediawiki.org/wiki/Special:PasswordReset
[POST]
wpUsername=<h1 style=background:red;position:absolute;top:0;left:0;width:1000px;height:1000px></h1>
Comment 1 Jesús Martínez Novo (Ciencia Al Poder) 2012-12-31 11:34:35 UTC
The username (in case it doesn't exist) is parsed as wikicode in the returned message, and it doesn't send disallowed tags like <script></script> as plain HTML but as text, so it doesn't seem to be something critical.

I'm not sure if that's an issue with the Special:PasswordReset message or if that's something more general about how we handle parameters in interface messages.

[Changed component: Wikimedia/Wikidata -> MediaWiki/General/Unknown]

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links