Page MenuHomePhabricator

$wgFileBlacklist should include 'xhtml'
Closed, ResolvedPublic

Description

Author: wonder

Description:
Along with the other html filetypes, .xhtml uploads should be blacklisted by default, because they could be a threat on a WM site that uses application/xhtml+xml, or even one that doesn't.


Version: 1.16.x
Severity: normal

Details

Reference
bz19355

Event Timeline

bzimport raised the priority of this task from to Medium.Nov 21 2014, 10:39 PM
bzimport set Reference to bz19355.

.xhtml and .xht added in r53487