Re: [tor-talk] XSS on blog.torproject.org - 8 month old ticket?

> By coincidence I stumbled on a 8 months old ticket reporting a XSS
> vulnerability on blog.torproject.org - and it is still vulnerable.
> This is not exactly inspiring confidence.
> I reassigned the ticket to phobos. Lets hope that this change something.
> https://trac.torproject.org/projects/tor/ticket/10440

The best way to see a change done is to do it yourself. Also see
https://trac.torproject.org/projects/tor/ticket/10022 which probably explains
why no one has fixed the XSS.

