antoniop
committed
on 14 Dec 23
Do not retrieve extra_css from query_parameters, as this is vulnerable to injections

Many thanks to Markus Moser