Comment 2 for bug 1822630

Revision history for this message
Jeff Davis (jdavis-sitka) wrote :

Fix pushed to branch user/jeffdavis/lp1822630-browse-xss in the security repo. Looks like a simple case of a CGI param being embedded in HTML without being sanitized with "param | html".