Page MenuHomePhabricator

Validate redirect destination in Wikimania Scholarships application
Closed, ResolvedPublic

Description

Security review feedback:

Wikimania/Scholarship/Controllers/Login.php

  • handlePost - sanity check $next before you redirect

Version: wmf-deployment
Severity: normal

Details

Reference
bz58305

Event Timeline

bzimport raised the priority of this task from to Unbreak Now!.Nov 22 2014, 2:41 AM
bzimport set Reference to bz58305.
bzimport added a subscriber: Unknown Object (MLST).

Change 100750 had a related patch set uploaded by BryanDavis:
Validate redirect destination on login

https://gerrit.wikimedia.org/r/100750

Change 100750 merged by jenkins-bot:
Validate redirect destination on login

https://gerrit.wikimedia.org/r/100750