No HTML quoting of address on "Subscription results" page

Bug #265991 reported by Peter Moulder
2
Affects Status Importance Assigned to Milestone
GNU Mailman
New
Medium
Unassigned

Bug Description

When subscribing using the web interface (e.g.
http://lists.sourceforge.net/lists/listinfo/inkscape-devel),
the resulting "mylist Subscription results" page
includes the literal text "<email address hidden>"
("Instructions are being sent to you at
<email address hidden>"), whereas HTML contains no such
element. Subscriber address ought to be html-escaped
using &lt;, &gt;, &amp;.

(Also, as mentioned in #596215, this page contains
other bad HTML such as an unterminated "<body" tag, and
a <html>...</html> element within a <BODY
...>...</body> element.)

version 2.0.9-sf.net

pjrm.

[http://sourceforge.net/tracker/index.php?func=detail&aid=851416&group_id=103&atid=100103]

Tags: web-cgi
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.