angler-fishThe Vulnerability History Project

Fixed is_safe_url() to reject URLs that use a scheme other than HTTP/S.

      This is a security fix; disclosure to follow shortly.
    
commit ae3535169af804352517b7fea94a42a1c9c4b762
+2 -6
+3 -4
expand_less