Skip to content

Conversation

@e0d
Copy link
Contributor

@e0d e0d commented Dec 17, 2013

PR for the last release of 2013.

e0d and others added 3 commits December 17, 2013 10:43
Several templates used a variable set by the user (the request host header).  This led to a vulnerability where an attacker could inject their domain name into these templates (i.e., activation emails).  This patch fixes this vulnerability.

LMS-532
Studio doesn't do email changes, thus has no email reset template; thus, we must disable password/email-reset related tests when running with studio settings
@e0d e0d merged commit 0d91e61 into release Dec 19, 2013
@flowerhack flowerhack deleted the rc/2013-12-18 branch June 11, 2014 15:48
jenkins-ks pushed a commit to nttks/edx-platform that referenced this pull request Jun 23, 2017
…openedx#1974)

* Fix review. add custom logo settings openedx#1873

* Fix bugs. add custom logo settings openedx#1972

* Fix bugs. add custom logo settings openedx#1971
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants