mirror of
https://github.com/go-gitea/gitea.git
synced 2024-11-29 20:45:38 +08:00
330bf8d3b3
There are likely problems remaining with the way that initCommentForm is creating its elements. I suspect that a malformed avatar url could be used maliciously. |
||
---|---|---|
.. | ||
draw.js | ||
index.js |