mirror of
https://github.com/discourse/discourse.git
synced 2024-12-14 08:43:40 +08:00
d8b68e00c9
The values in Discourse dropdown menus only come from admin-defined strings, not unsanitised end-user input, so this lack of escaping was not exploitable. |
||
---|---|---|
.. | ||
addon | ||
app | ||
config | ||
.npmrc | ||
ember-cli-build.js | ||
index.js | ||
package.json |