stable

Clone or download

Read-only

Project name should be properly escaped in project status change notification

The project name must be escaped in the HTML email otherwise the HTML will be rendered by the mail client. Issue can be seen with a project name like "<img src=https://example.com/image.png>". Part of request #12791: Fix html purification for project privacy change Change-Id: Ia4f04f2dd9d125cabcaa98c017862466dd852dd2

Modified Files

Name
M src/common/system_event/include/SystemEvent_PROJECT_IS_PRIVATE.class.php +5 −7 Go to diff View file