MantisBT: master 66c142dc
| Author | Committer | Branch | Timestamp | Parent |
|---|---|---|---|---|
| dregad | dregad | master | 2014-11-27 14:15 | master b35d3436 |
| Affected Issues | 0017297: CVE-2014-9272: XSS in string_insert_hrefs allows script execution | |||
| Changeset | Fix 0017297: XSS in string_insert_hrefs The URL matching regex in the function did not validate the protocol, Issue was discovered by Mathias Karlsson (http://mathiaskarlsson.me) |
|||
| mod - core/string_api.php | Diff File | |||