mirror of
https://github.com/discourse/discourse.git
synced 2024-12-14 20:03:43 +08:00
477bacb3ae
The XSS here is only possible if CSP is disabled. Low impact since CSP is enabled by default in SiteSettings. |
||
---|---|---|
.. | ||
assets | ||
controllers | ||
helpers | ||
jobs | ||
mailers | ||
models | ||
serializers | ||
services | ||
views |