[mantisbt-commits] [mantisbt/mantisbt] 610da6: filter api: always
treat FILTER_PROPERTY_MATCH_TYP...
From: GitHub <no...@gi...> - 2013-01-18 20:30:01
|
Branch: refs/heads/master-1.2.x Home: https://github.com/mantisbt/mantisbt Commit: 610da6ecda08239187bc12bf9bf35ba4d27f1920 https://github.com/mantisbt/mantisbt/commit/610da6ecda08239187bc12bf9bf35ba4d27f1920 Author: Robert Munteanu <ro...@lm...> Date: 2013-01-18 (Fri, 18 Jan 2013) Changed paths: M core/filter_api.php M view_all_set.php Log Message: ----------- filter api: always treat FILTER_PROPERTY_MATCH_TYPE as an int value Based on @dregad's comments, this follows up on @dhx's fix. Fixes #15373: XSS vulnerability |