Pending

User tests: Successful: Unsuccessful:

avatar n3t
n3t
28 Jan 2012

In Joomla 2.5 mod_menu rendering of menu items of type alias and url calls htmlspecialchars for item url.
But this is already processed by helper of mod%menu by calling JRoute::_() function. It results in invalid urls.

avatar n3t n3t - open - 28 Jan 2012
avatar infograf768
infograf768 - comment - 29 Jan 2012

Please create a tracker on joomlacode

avatar elinw
elinw - comment - 29 Jan 2012

Unfortunately just reverting will simply recreate the security issue of allowing dangerous strings to be saved.

avatar realityking
realityking - comment - 30 Jan 2012

I'm confused, either the string is double encoded or not. If it was encoded before there shouldn't have been an issue. This doesn't make sense to me.

avatar infograf768 infograf768 - close - 1 Feb 2012
avatar infograf768
infograf768 - comment - 1 Feb 2012

Corrected through new patch in tracker

avatar coolbung coolbung - reference | 885eab7 - 23 Aug 13

Add a Comment

Login with GitHub to post a comment