mirror of
https://github.com/discourse/discourse.git
synced 2025-02-23 22:58:39 +08:00

This isn't a security bug, because only admins can create user fields and we have to trust admins, because they can change themes, which are shown site-wide and can contain unrestricted JS.