mirror of
https://github.com/discourse/discourse.git
synced 2025-03-04 23:09:39 +08:00

The values in Discourse dropdown menus only come from admin-defined strings, not unsanitised end-user input, so this lack of escaping was not exploitable.