Skip to content

Commit 414353d

Browse files
ENGCOM-3145: Prevent XSS on checkout #18487
- Merge Pull Request #18487 from samgranger/magento2:2.3-develop - Merged commits: 1. 1e11b5c 2. 880622b 3. f9bde40
2 parents a474225 + f9bde40 commit 414353d

File tree

3 files changed

+3
-3
lines changed

3 files changed

+3
-3
lines changed

app/code/Magento/Checkout/view/frontend/web/template/billing-address/details.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
<text args="currentBillingAddress().prefix"/> <text args="currentBillingAddress().firstname"/> <text args="currentBillingAddress().middlename"/>
99
<text args="currentBillingAddress().lastname"/> <text args="currentBillingAddress().suffix"/><br/>
1010
<text args="_.values(currentBillingAddress().street).join(', ')"/><br/>
11-
<text args="currentBillingAddress().city "/>, <span html="currentBillingAddress().region"></span> <text args="currentBillingAddress().postcode"/><br/>
11+
<text args="currentBillingAddress().city "/>, <span text="currentBillingAddress().region"></span> <text args="currentBillingAddress().postcode"/><br/>
1212
<text args="getCountryName(currentBillingAddress().countryId)"/><br/>
1313
<a if="currentBillingAddress().telephone" attr="'href': 'tel:' + currentBillingAddress().telephone" text="currentBillingAddress().telephone"></a><br/>
1414

app/code/Magento/Checkout/view/frontend/web/template/shipping-address/address-renderer/default.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
<text args="address().prefix"/> <text args="address().firstname"/> <text args="address().middlename"/>
99
<text args="address().lastname"/> <text args="address().suffix"/><br/>
1010
<text args="_.values(address().street).join(', ')"/><br/>
11-
<text args="address().city "/>, <span html="address().region"></span> <text args="address().postcode"/><br/>
11+
<text args="address().city "/>, <span text="address().region"></span> <text args="address().postcode"/><br/>
1212
<text args="getCountryName(address().countryId)"/><br/>
1313
<a if="address().telephone" attr="'href': 'tel:' + address().telephone" text="address().telephone"></a><br/>
1414

app/code/Magento/Checkout/view/frontend/web/template/shipping-information/address-renderer/default.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
<text args="address().prefix"/> <text args="address().firstname"/> <text args="address().middlename"/>
99
<text args="address().lastname"/> <text args="address().suffix"/><br/>
1010
<text args="_.values(address().street).join(', ')"/><br/>
11-
<text args="address().city "/>, <span html="address().region"></span> <text args="address().postcode"/><br/>
11+
<text args="address().city "/>, <span text="address().region"></span> <text args="address().postcode"/><br/>
1212
<text args="getCountryName(address().countryId)"/><br/>
1313
<a if="address().telephone" attr="'href': 'tel:' + address().telephone" text="address().telephone"></a><br/>
1414

0 commit comments

Comments
 (0)