line 2913 added urlencode There was a cross site scripting vulnerability due to insufficient input sanitation on the $pg parameter. This patch fixes that issue.