mirror of
https://github.com/go-gitea/gitea
synced 2025-02-07 06:47:02 +01:00
330bf8d3b3
There are likely problems remaining with the way that initCommentForm is creating its elements. I suspect that a malformed avatar url could be used maliciously.