Page MenuHomePhabricator

FancyCaptcha uses unescaped i18n messages
Closed, ResolvedPublicSecurity

Description

captcha-label and fancycaptcha-captcha can be used to include raw HTML on pages that display a captcha box.

Details

Risk Rating
Low
Author Affiliation
WMF Technology Dept

Event Timeline


Let me know if you'd prefer using Gerrit, not sure how seriously this kind of problem should be taken.

CR+1

Let me know if you'd prefer using Gerrit, not sure how seriously this kind of problem should be taken.

ConfirmEdit is bundled, but these message sanitization issues should mostly be low-risk, so it should be fine to push through gerrit.

sbassett added a parent task: Restricted Task.Nov 13 2024, 3:26 PM

Resolved now, right? Or are you waiting for the MW release to close this?

Resolved now, right? Or are you waiting for the MW release to close this?

Yes, I believe this is resolved. Since we deemed this low-risk and the patches were public, it's fine to make this task public. I just added the tracking parent task so @Reedy could have the option of mentioning it in the next core security release and to potentially backport the patch, if desired.

sbassett triaged this task as Low priority.
sbassett changed the visibility from "Custom Policy" to "Public (No Login Required)".
sbassett changed the edit policy from "Custom Policy" to "All Users".
sbassett changed Risk Rating from N/A to Low.