The values in Discourse dropdown menus only come from admin-defined strings, not unsanitised end-user input, so this lack of escaping was not exploitable. |
||
|---|---|---|
| .. | ||
| category-drop | ||
| color-palettes | ||
| combo-box | ||
| dropdown-select-box | ||
| future-date-input-selector | ||
| mini-tag-chooser | ||
| multi-select | ||
| notifications-filter | ||
| period-chooser | ||
| select-kit | ||
| tag-drop | ||
| toolbar-popup-menu-options | ||
| user-chooser | ||
| category-row.hbs | ||
| create-color-row.hbs | ||
| email-group-user-chooser-row.hbs | ||
| flair-row.hbs | ||
| multi-select.hbs | ||
| pinned-button.hbs | ||
| selected-choice-category.hbs | ||
| selected-choice.hbs | ||
| selected-name.hbs | ||
| single-select.hbs | ||
| tag-chooser-row.hbs | ||
| tag-row.hbs | ||
| topic-notifications-button.hbs | ||
| topic-row.hbs | ||