Fixing email link injection bug
Several templates used a variable set by the user (the request host header). This led to a vulnerability where an attacker could inject their domain name into these templates (i.e., activation emails). This patch fixes this vulnerability. LMS-532
Showing
common/djangoapps/util/request.py
0 → 100644
common/djangoapps/util/tests/test_request.py
0 → 100644
Please
register
or
sign in
to comment