mirror of
https://github.com/tenrok/bootstrap.git
synced 2026-06-11 18:02:28 +03:00
Fix/xss issues on data attributes (#27047)
* fix(collapse): xss CVE-2018-14040 Fixes #26625 * fix(tooltip): xss CVE-2018-14042 Fixes #26628 * fix(tooltip): XSS on data-viewport attribute Fixes #27044 * fix(affix): XSS on target config Fixes #27045
This commit is contained in:
@@ -104,4 +104,19 @@ $(function () {
|
||||
}, 250)
|
||||
}, 250)
|
||||
})
|
||||
|
||||
QUnit.test('should raise exception to avoid xss on target', function (assert) {
|
||||
assert.expect(1)
|
||||
assert.throws(function () {
|
||||
|
||||
var templateHTML = '<div id="affixTarget"></div>'
|
||||
$(templateHTML).appendTo(document.body)
|
||||
|
||||
$('#affixTarget').bootstrapAffix({
|
||||
target: '<img src=1 onerror=\'alert(0)\'>'
|
||||
})
|
||||
|
||||
}, new Error('Syntax error, unrecognized expression: <img src=1 onerror=\'alert(0)\'>'))
|
||||
})
|
||||
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user