Skip to content

Commit 880622b

Browse files
authored
Do not output html for region field due to xss
1 parent 1e11b5c commit 880622b

File tree

1 file changed

+1
-1
lines changed
  • app/code/Magento/Checkout/view/frontend/web/template/shipping-information/address-renderer

1 file changed

+1
-1
lines changed

app/code/Magento/Checkout/view/frontend/web/template/shipping-information/address-renderer/default.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
<text args="address().prefix"/> <text args="address().firstname"/> <text args="address().middlename"/>
99
<text args="address().lastname"/> <text args="address().suffix"/><br/>
1010
<text args="_.values(address().street).join(', ')"/><br/>
11-
<text args="address().city "/>, <span html="address().region"></span> <text args="address().postcode"/><br/>
11+
<text args="address().city "/>, <span text="address().region"></span> <text args="address().postcode"/><br/>
1212
<text args="getCountryName(address().countryId)"/><br/>
1313
<a if="address().telephone" attr="'href': 'tel:' + address().telephone" text="address().telephone"></a><br/>
1414

0 commit comments

Comments
 (0)