Dan Brown
349162ea13
Prevented possible XSS via link attachments
...
This filters out potentially malicious javascript: or data: uri's coming
through to be attached to attachments.
Added tests to cover.
Thanks to Yassine ABOUKIR (@yassineaboukir on twitter) for reporting this
vulnerability.
2020-10-31 15:01:52 +00:00
..
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-26 17:46:32 +01:00
2020-09-20 10:28:01 +01:00
2020-09-26 17:46:32 +01:00
2020-09-26 17:46:32 +01:00
2020-10-31 15:01:52 +00:00
2020-10-02 17:18:27 +01:00
2020-09-26 17:46:32 +01:00
2020-09-19 15:22:32 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-19 15:22:32 +01:00
2020-09-20 10:28:01 +01:00
2020-09-26 17:46:32 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-19 15:22:32 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-09-20 10:28:01 +01:00
2020-10-05 06:26:38 +01:00
2020-09-20 10:28:01 +01:00