Index: branches/REL1_16/phase3/RELEASE-NOTES |
— | — | @@ -45,12 +45,15 @@ |
46 | 46 | further. |
47 | 47 | |
48 | 48 | == Changes since 1.16.2 == |
| 49 | + |
49 | 50 | * (bug 28449) Fixed permissions checks in Special:Import which allowed users |
50 | 51 | without the 'import' permission to import pages from the configured import |
51 | 52 | sources. |
52 | 53 | * (bug 28235) Fixed XSS affecting IE 6 and earlier clients only, due to those |
53 | 54 | browsers looking for a file extension in the query string of the URL, and |
54 | 55 | ignoring the Content-Type header if one is found. |
| 56 | +* (bug 28450) Fixed a CSS validation issue involving escaped comments, which |
| 57 | + led to XSS for Internet Explorer clients and privacy loss for other clients. |
55 | 58 | |
56 | 59 | == Changes since 1.16.1 == |
57 | 60 | |