Comment 13 for bug 1942903

Revision history for this message
Mahara Bot (dev-mahara) wrote : A change has been merged

Reviewed: https://reviews.mahara.org/12203
Committed: https://git.mahara.org/mahara/mahara/commit/7d94b9e9f87b1235d51f59f8db2d57caf7edd09b
Submitter: Gold (<email address hidden>)
Branch: 21.04_STABLE

commit 7d94b9e9f87b1235d51f59f8db2d57caf7edd09b
Author: Robert Lyon <email address hidden>
Date: Thu Sep 23 09:48:23 2021 +1200

Security bug 1942903: PDF export can cause command injection vulnerability

When a person names a collection in a certain way the title can be
executed when merging the PDF pages into one collection PDF

Change-Id: Iccca05291d79fe634b40cca11dcc9153a412ab86
Signed-off-by: Robert Lyon <email address hidden>
(cherry picked from commit ff1a3446f5c2a4c0ca35a0f1470d9483d028efdd)
(cherry picked from commit 79442bf3879049a5e49f4c1891bbd26570ac27a8)