angler-fishThe Vulnerability History Project

Fixed is_safe_url() to reject URLs that use a scheme other than HTTP/S.

      This is a security fix; disclosure to follow shortly.
    
commit ec67af0bd609c412b76eaa4cc89968a2a8e5ad6a
+2 -6
+3 -4
expand_less