Merge "Make Revision::getText() emit deprecation warnings."
[lhc/web/wiklou.git] / includes / Sanitizer.php
index c81c7bb..4069658 100644 (file)
@@ -1015,6 +1015,7 @@ class Sanitizer {
                                | url\s*\(
                                | image\s*\(
                                | image-set\s*\(
+                               | attr\s*\([^)]+[\s,]+url
                        !ix', $value ) ) {
                        return '/* insecure input */';
                }