Person CSV import view does not sanitize user ids
Bug #251868 reported by
Ignas Mikalajūnas
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
SchoolTool |
Fix Released
|
Medium
|
Douglas Cerna |
Bug Description
Just try importing "@@index.html, Mister, Index"
and accessing that user.
Changed in schooltool: | |
assignee: | nobody → ignas |
importance: | Undecided → Medium |
status: | New → Confirmed |
Changed in schooltool: | |
milestone: | none → jaunty |
Changed in schooltool: | |
assignee: | Ignas Mikalajūnas (ignas) → Douglas Cerna (replaceafill) |
status: | Confirmed → In Progress |
Changed in schooltool: | |
status: | In Progress → Fix Committed |
Changed in schooltool: | |
status: | Fix Committed → Fix Released |
To post a comment you must log in.