mirror of
https://gh.wpcy.net/https://github.com/discourse/discourse.git
synced 2026-06-17 11:28:14 +08:00
The XSS here is only possible if CSP is disabled. Low impact since CSP is enabled by default in SiteSettings. |
||
|---|---|---|
| .. | ||
| images | ||
| javascripts | ||
| stylesheets | ||