Created on 10 January 2016, almost 9 years ago
Updated 12 June 2024, 7 months ago

Looking through the code, drupal_get_query_parameters() doesn't do any input sanitization, and there isn't any in the class, it passes the parameter straight into the View. Is that present in the parent? If not, should this be wrapped in check_plain()?

πŸ› Bug report
Status

Needs work

Version

1.1

Component

Code

Created by

πŸ‡¨πŸ‡¦Canada Renee S

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024