Skip to content

Commit da3bfbf

Browse files
authored
[Security] IBX-10200: Fix XSS in reschedule/cancel-schedule modal
1 parent acaa620 commit da3bfbf

File tree

2 files changed

+6
-1
lines changed

2 files changed

+6
-1
lines changed

src/bundle/Resources/public/js/scripts/fieldType/ezimageasset.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -155,7 +155,7 @@
155155
previewImg.classList.toggle('d-none', image === null);
156156
previewAlt.value = image.alternativeText;
157157
previewActionPreview.setAttribute('href', destinationLocationUrl);
158-
assetNameContainer.innerHTML = destinationContentName;
158+
assetNameContainer.innerText = destinationContentName;
159159
assetNameContainer.setAttribute('href', destinationLocationUrl);
160160

161161
this.inputDestinationContentId.value = destinationContentId;

src/bundle/Resources/public/js/scripts/helpers/dom.helper.js

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,9 +14,14 @@
1414
node.insertAdjacentHTML(position, escapedText);
1515
};
1616

17+
const dangerouslyAppend = (node, nodeOrText) => {
18+
node.append(nodeOrText);
19+
};
20+
1721
eZ.addConfig('helpers.dom', {
1822
safelySetInnerHTML,
1923
dangerouslySetInnerHTML,
2024
dangerouslyInsertAdjacentHTML,
25+
dangerouslyAppend,
2126
});
2227
})(window, window.document, window.eZ);

0 commit comments

Comments
 (0)