mirror of
https://gh.wpcy.net/https://github.com/discourse/discourse.git
synced 2026-05-08 17:00:16 +08:00
When quoting from a channel or a thread, the title of the channel and the title of the thread could be an XSS vector when CSP is disabled. |
||
|---|---|---|
| .. | ||
| javascripts | ||
| stylesheets | ||