mirror of
https://github.com/discourse/discourse.git
synced 2025-02-24 22:45:27 +00:00
The watch words controller creation function, create_or_update_word(), doesn’t validate the size of the replacement parameter, unlike the word parameter, when creating a replace watched word. So anyone with moderator privileges can create watched words with almost unlimited characters.