Index: t3lib/class.t3lib_div.php =================================================================== --- t3lib/class.t3lib_div.php (Revision 6510) +++ t3lib/class.t3lib_div.php (Arbeitskopie) @@ -4120,7 +4120,7 @@ ); // Pass if URL is on the current host: - if (self::isValidUrl($decodedUrl)) { + if (self::isValidUrl($decodedUrl) && preg_match('#^[a-z0-9]+://#', $decodedUrl)) { if (self::isOnCurrentHost($decodedUrl) && strpos($decodedUrl, self::getIndpEnv('TYPO3_SITE_URL')) === 0) { $sanitizedUrl = $url; }