Closed jeffersoncasimir closed 2 days ago
related to this report per Samir (Nov.22): Shen to install 23 and test the fix against these attacks, and issue the PR if it works.
This fix is not working in my VM.
This is another way to fix this issue. #9481 test from here http://wangshen-dev.loris.ca/login/request-account/
Replaced by above
The following is a patch that can potentially address the XSS vulnerability of the request_account page:
Patch for
modules/login/templates/form_requestaccount.tpl
: