mirror of
https://gh.wpcy.net/https://github.com/discourse/discourse.git
synced 2026-05-09 14:18:58 +08:00
When quoting from a channel or a thread, the title of the channel and the title of the thread could be an XSS vector when CSP is disabled. |
||
|---|---|---|
| .. | ||
| discourse | ||
| lib | ||