mirror of
https://github.com/BookStackApp/BookStack.git
synced 2025-10-26 11:11:56 +00:00
This filters out potentially malicious javascript: or data: uri's coming through to be attached to attachments. Added tests to cover. Thanks to Yassine ABOUKIR (@yassineaboukir on twitter) for reporting this vulnerability. |
||
|---|---|---|
| .. | ||
| AttachmentTest.php | ||
| AvatarTest.php | ||
| DrawioTest.php | ||
| ImageTest.php | ||
| UsesImages.php | ||