mirror of
https://gh.wpcy.net/https://github.com/discourse/discourse.git
synced 2026-04-29 13:28:22 +08:00
SQL injection in PM tag filtering (`list_private_messages_tag`) allows bypassing tag filter conditions, potentially disclosing unauthorized private message metadata. |
||
|---|---|---|
| .. | ||
| private_message_lists.rb | ||