mirror of
https://gh.wpcy.net/https://github.com/discourse/discourse.git
synced 2026-05-06 07:17:27 +08:00
When quoting from a channel or a thread, the title of the channel and the title of the thread could be an XSS vector when CSP is disabled. |
||
|---|---|---|
| .. | ||
| discourse-markdown | ||
| rich-editor-extension.js | ||