mirror of https://github.com/docusealco/docuseal
params[:redir] was used directly without validation, allowing redirects to external URLs. Now only allows relative paths.pull/656/head
parent
744d45d2c5
commit
3095240a07
Loading…
Reference in new issue