mirror of
https://github.com/opensourcepos/opensourcepos.git
synced 2026-03-08 00:59:04 -05:00
Fix XSS vulnerability in attributes (#3965)
This commit is contained in:
@@ -192,7 +192,7 @@
|
||||
}
|
||||
}
|
||||
|
||||
$('#definition_list_group').append('<li class="list-group-item">' + value + '<a href="javascript:void(0);"><span class="glyphicon glyphicon-trash pull-right"></span></a></li>')
|
||||
$('#definition_list_group').append('<li class="list-group-item">' + DOMPurify.sanitize(value) + '<a href="javascript:void(0);"><span class="glyphicon glyphicon-trash pull-right"></span></a></li>')
|
||||
.find(':last-child a').click(remove_attribute_value);
|
||||
$('#definition_value').val('');
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user