mirror of
https://gitee.com/gitea/gitea
synced 2025-12-02 22:30:35 +08:00
There are likely problems remaining with the way that initCommentForm is creating its elements. I suspect that a malformed avatar url could be used maliciously.