Comment 15 for bug 1453074

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: help_text parameter of fields is vulnerable to arbitrary html injection (CVE-2015-3219)

Tristan's impact description in comment #6 looks good to me, and I agree that the disclosure schedule in comment #14 is reasonable.