Files
BookStack/tests
Dan Brown 349162ea13 Prevented possible XSS via link attachments
This filters out potentially malicious javascript: or data: uri's coming
through to be attached to attachments.
Added tests to cover.

Thanks to Yassine ABOUKIR (@yassineaboukir on twitter) for reporting this
vulnerability.
2020-10-31 15:01:52 +00:00
..
2020-05-23 00:28:41 +01:00
2020-09-26 18:24:05 +01:00
2020-09-19 12:06:45 +01:00
2019-09-13 23:58:40 +01:00