angler-fishThe Vulnerability History Project

Fixed is_safe_url() to reject URLs that use a scheme other than HTTP/S.

      This is a security fix; disclosure to follow shortly.
    
commit 1a274ccd6bc1afbdac80344c9b6e5810c1162b5f
+2 -6
+3 -4
expand_less