mirror of
https://github.com/discourse/discourse.git
synced 2025-02-07 11:58:27 +00:00
The values in Discourse dropdown menus only come from admin-defined strings, not unsanitised end-user input, so this lack of escaping was not exploitable.