diff options
author | Jo-Philipp Wich <jo@mein.io> | 2021-12-23 17:06:09 +0100 |
---|---|---|
committer | Jo-Philipp Wich <jo@mein.io> | 2021-12-23 17:08:21 +0100 |
commit | 993151504e8e810c083d3257555bdcdc2f00673a (patch) | |
tree | 011ed8da414f36857a689cc8d95b479d24b6864c /applications/luci-app-mwan3 | |
parent | cac0349d26445dc023af69fa8788ca1d2d8f70d4 (diff) |
luci-base: form.js: do not execute embedded script code in stripTags()
Instead of relying on .innerHTML which executes embedded script code to
parse a given HTML fragment, use dom.parse() which utilizies DOMParser()
internally in order to extract textContent in a safe manner.
Fixes: FS#4199
Ref: https://bugs.openwrt.org/index.php?do=details&task_id=4199
Signed-off-by: Jo-Philipp Wich <jo@mein.io>
Diffstat (limited to 'applications/luci-app-mwan3')
0 files changed, 0 insertions, 0 deletions