The XSS here is only possible if CSP is disabled. Low impact since CSP is enabled by default in SiteSettings.
9a11a8b3
[description|attachment](upload://<short-sha>)