mirror of
https://github.com/discourse/discourse.git
synced 2025-02-10 13:24:55 +00:00
The values in Discourse dropdown menus only come from admin-defined strings, not unsanitised end-user input, so this lack of escaping was not exploitable.