Skip to content

Commit 860b2aa

Browse files
ENGCOM-3182: [Backport] Prevent XSS on checkout #18587
- Merge Pull Request #18587 from dmytro-ch/magento2:2.2-develop-PR-port-18487 - Merged commits: 1. e1b5f51 2. c1a7d19 3. fca4023
2 parents 4a6b81f + fca4023 commit 860b2aa

File tree

3 files changed

+3
-3
lines changed

3 files changed

+3
-3
lines changed

app/code/Magento/Checkout/view/frontend/web/template/billing-address/details.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
<text args="currentBillingAddress().prefix"/> <text args="currentBillingAddress().firstname"/> <text args="currentBillingAddress().middlename"/>
99
<text args="currentBillingAddress().lastname"/> <text args="currentBillingAddress().suffix"/><br/>
1010
<text args="_.values(currentBillingAddress().street).join(', ')"/><br/>
11-
<text args="currentBillingAddress().city "/>, <span html="currentBillingAddress().region"></span> <text args="currentBillingAddress().postcode"/><br/>
11+
<text args="currentBillingAddress().city "/>, <span text="currentBillingAddress().region"></span> <text args="currentBillingAddress().postcode"/><br/>
1212
<text args="getCountryName(currentBillingAddress().countryId)"/><br/>
1313
<a if="currentBillingAddress().telephone" attr="'href': 'tel:' + currentBillingAddress().telephone" text="currentBillingAddress().telephone"></a><br/>
1414

app/code/Magento/Checkout/view/frontend/web/template/shipping-address/address-renderer/default.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
<text args="address().prefix"/> <text args="address().firstname"/> <text args="address().middlename"/>
99
<text args="address().lastname"/> <text args="address().suffix"/><br/>
1010
<text args="_.values(address().street).join(', ')"/><br/>
11-
<text args="address().city "/>, <span html="address().region"></span> <text args="address().postcode"/><br/>
11+
<text args="address().city "/>, <span text="address().region"></span> <text args="address().postcode"/><br/>
1212
<text args="getCountryName(address().countryId)"/><br/>
1313
<a if="address().telephone" attr="'href': 'tel:' + address().telephone" text="address().telephone"></a><br/>
1414

app/code/Magento/Checkout/view/frontend/web/template/shipping-information/address-renderer/default.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
<text args="address().prefix"/> <text args="address().firstname"/> <text args="address().middlename"/>
99
<text args="address().lastname"/> <text args="address().suffix"/><br/>
1010
<text args="_.values(address().street).join(', ')"/><br/>
11-
<text args="address().city "/>, <span html="address().region"></span> <text args="address().postcode"/><br/>
11+
<text args="address().city "/>, <span text="address().region"></span> <text args="address().postcode"/><br/>
1212
<text args="getCountryName(address().countryId)"/><br/>
1313
<a if="address().telephone" attr="'href': 'tel:' + address().telephone" text="address().telephone"></a><br/>
1414

0 commit comments

Comments
 (0)