There are likely problems remaining with the way that initCommentForm is creating its elements. I suspect that a malformed avatar url could be used maliciously. |
||
|---|---|---|
| .. | ||
| css | ||
| img | ||
| js | ||
| less | ||
| vendor | ||
There are likely problems remaining with the way that initCommentForm is creating its elements. I suspect that a malformed avatar url could be used maliciously. |
||
|---|---|---|
| .. | ||
| css | ||
| img | ||
| js | ||
| less | ||
| vendor | ||