From 1e11b5c5c60f54849ad0e934f036d3cb08a65575 Mon Sep 17 00:00:00 2001 From: Sam Granger Date: Tue, 9 Oct 2018 15:36:02 +0200 Subject: [PATCH 1/3] Do not output html for region field due to xss --- .../web/template/shipping-address/address-renderer/default.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/code/Magento/Checkout/view/frontend/web/template/shipping-address/address-renderer/default.html b/app/code/Magento/Checkout/view/frontend/web/template/shipping-address/address-renderer/default.html index 05ced7a978f82..2a5dc27328a43 100644 --- a/app/code/Magento/Checkout/view/frontend/web/template/shipping-address/address-renderer/default.html +++ b/app/code/Magento/Checkout/view/frontend/web/template/shipping-address/address-renderer/default.html @@ -8,7 +8,7 @@

- ,
+ ,


From 880622b3f6b827d30f4bbb6677b7d7fb5fc9caaa Mon Sep 17 00:00:00 2001 From: Sam Granger Date: Tue, 9 Oct 2018 15:36:44 +0200 Subject: [PATCH 2/3] Do not output html for region field due to xss --- .../template/shipping-information/address-renderer/default.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/code/Magento/Checkout/view/frontend/web/template/shipping-information/address-renderer/default.html b/app/code/Magento/Checkout/view/frontend/web/template/shipping-information/address-renderer/default.html index 97286a28552d2..541413955cb47 100644 --- a/app/code/Magento/Checkout/view/frontend/web/template/shipping-information/address-renderer/default.html +++ b/app/code/Magento/Checkout/view/frontend/web/template/shipping-information/address-renderer/default.html @@ -8,7 +8,7 @@

- ,
+ ,


From f9bde4091d147c65944f2e08cad1c84650ca952f Mon Sep 17 00:00:00 2001 From: Sam Granger Date: Tue, 9 Oct 2018 15:37:48 +0200 Subject: [PATCH 3/3] Do not output html for region field due to xss --- .../view/frontend/web/template/billing-address/details.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/code/Magento/Checkout/view/frontend/web/template/billing-address/details.html b/app/code/Magento/Checkout/view/frontend/web/template/billing-address/details.html index cc1d960bbe44b..ea521b3a8afd4 100644 --- a/app/code/Magento/Checkout/view/frontend/web/template/billing-address/details.html +++ b/app/code/Magento/Checkout/view/frontend/web/template/billing-address/details.html @@ -8,7 +8,7 @@

- ,
+ ,