2.2.7 Cross Site Scripting Vulnerability
Closed this issue · 5 comments
fgeek commented
halamix2 commented
I'll publish Search.php fix shortly but I were unable to reproduce POST XSS in profile.php
( I'm not sure if it wasn't fixed in this commit ).
Edit: I see it now
fgeek commented
CVE-2015-2217 has been assigned for this issue. Please use it in your ChangeLog when releasing new version, thanks. Could you create new release with this fix, thanks?
phpcodex commented
I'll have a look in to this issue, it would need confirming that it is fixed before we release the next version.
phpcodex commented
So looking at this, it is not fixed, but we have to cURL it to do the final test as I can't replicate.
phpcodex commented
Okay, this is official, bug has been previously sanitized. Cannot reproduce. I can change all the detail's in cURL but unable to create the bug, even using the original CVE.