mirror of
https://github.com/discourse/discourse.git
synced 2026-08-06 11:36:31 +08:00
SQL injection in PM tag filtering (`list_private_messages_tag`) allows bypassing tag filter conditions, potentially disclosing unauthorized private message metadata. |
||
|---|---|---|
| .. | ||
| private_message_lists.rb | ||