Merge pull request #3037 from DevelopmentDocumentopia/xss_clean_patch

xss_clean is not protecting GET requests that &item=/startwithslash