Skip to content

Commit afd269e

Browse files
Fixed XSS vulnerability in avatarURL in Likes block (#35747)
* Fixed XSS vulnerability in avatarURL in Likes block * changelog * Update changelog --------- Co-authored-by: Ivan Ottinger <[email protected]>
1 parent f0fa2c8 commit afd269e

File tree

2 files changed

+6
-2
lines changed

2 files changed

+6
-2
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
Significance: patch
2+
Type: bugfix
3+
4+
Like block: Encode Avatar URLs

projects/plugins/jetpack/modules/likes/queuehandler.js

+2-2
Original file line numberDiff line numberDiff line change
@@ -241,7 +241,7 @@ function JetpackLikesMessageListener( event ) {
241241
if ( newLayout ) {
242242
element.innerHTML = `
243243
<a href="${ encodeURI( liker.profile_URL ) }" rel="nofollow" target="_parent" class="wpl-liker">
244-
<img src="${ liker.avatar_URL }"
244+
<img src="${ encodeURI( liker.avatar_URL ) }"
245245
alt=""
246246
style="width: 28px; height: 28px;" />
247247
<span></span>
@@ -250,7 +250,7 @@ function JetpackLikesMessageListener( event ) {
250250
} else {
251251
element.innerHTML = `
252252
<a href="${ encodeURI( liker.profile_URL ) }" rel="nofollow" target="_parent" class="wpl-liker">
253-
<img src="${ liker.avatar_URL }"
253+
<img src="${ encodeURI( liker.avatar_URL ) }"
254254
alt=""
255255
style="width: 30px; height: 30px; padding-right: 3px;" />
256256
</a>

0 commit comments

Comments
 (0)