mirror of
https://github.com/BookStackApp/BookStack.git
synced 2025-03-05 01:07:39 +08:00

This filters out potentially malicious javascript: or data: uri's coming through to be attached to attachments. Added tests to cover. Thanks to Yassine ABOUKIR (@yassineaboukir on twitter) for reporting this vulnerability.