Skip to content

[5.10]: returnUrl encoding not compatible with Apache #18923

@HannahDeWachter

Description

@HannahDeWachter

What happened?

Description

After updating to Craft 5.10.1 I tried testing the update on a staging environment, but when I tried opening elements (Entry, Form, User) in the backend I got a Forbidden error. When looking at the acces logs of the server I saw following error: Unsafe URL with %3f URL rewritten without UnsafeAllow3F
Our server provider told us it does not meet the requirements of Apache.

Example of an url giving the error: https://stagingwebsite.com/admin/myaccount?returnUrl=https%3A//stagingwebsite.com/admin/users/all%3Fsource%3D%2A

Craft CMS version

5.10.1

PHP version

8.3

Operating system and version

Linux

Database type and version

MySQL 8.0

Image driver and version

Imagick

Installed plugins and versions

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions