Please sign in to comment.
Backport 7eec482 to 2.x
Backport fixes to base path generation that prevent issue when a URL contains // it can circumvent the base path generation, which results in unwanted user data in the base/webroot paths. This creates an opportunity for CSS manipulation in old versions of IE, and newer ones via iframe inheritance.
- Loading branch information...
Showing with 20 additions and 0 deletions.