[Backport] Prevent XSS on checkout #18587
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Original Pull Request
#18487
Description
The State/Province field (when selecting a country like The Netherlands) gives the user an input field (in checkout/account address). When filling <script>alert('hello world')</script>, the user will experience self xss in the next step of the checkout.
Fixed Issues (if relevant)
Bugcrowd reference cd8d0c3b57686f09cde51c4afaa2f0e70e51f9093121fb7140e3b7f26a89b7fd (which got marked as "won't fix")
Manual testing scenarios
See description/ (bugcrowd for video)
Contribution checklist