mirror of
https://github.com/discourse/discourse.git
synced 2024-11-30 06:43:37 +08:00
a373bf2a01
Non-markdown tags weren't being escaped in chat excerpts. This could be triggered by editing a chat message containing a tag (self XSS), or by replying to a chat message with a tag (XSS). Co-authored-by: Jan Cernik <jancernik12@gmail.com> |
||
---|---|---|
.. | ||
addon | ||
app | ||
config | ||
tests | ||
.npmrc | ||
ember-cli-build.js | ||
index.js | ||
jsconfig.json | ||
package.json |