mirror of
https://github.com/discourse/discourse.git
synced 2024-12-05 04:13:41 +08:00
d8b68e00c9
The values in Discourse dropdown menus only come from admin-defined strings, not unsanitised end-user input, so this lack of escaping was not exploitable. |
||
---|---|---|
.. | ||
images | ||
javascripts | ||
stylesheets |