Skip to content

Commit b2d3cf5

Browse files
Merge pull request #725 from tomaioo/fix/security/arbitrary-code-execution-via-eval-in-men
fix(security): 2 improvements across 2 files
2 parents e4b9e44 + 2413838 commit b2d3cf5

2 files changed

Lines changed: 2 additions & 2 deletions

File tree

app/model/GroupModule.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ Ext.define('MBilling.model.GroupModule', {
1717
name: 'idModuletext',
1818
type: 'string',
1919
convert: function(value) {
20-
return eval(value);
20+
return value;
2121
}
2222
}, {
2323
name: 'show_menu',

app/model/Menu.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ Ext.define('MBilling.model.Menu', {
2424
fields: [{
2525
name: 'text',
2626
convert: function(value) {
27-
return (value.indexOf('t(') !== -1) ? eval(value) : value;
27+
return value;
2828
}
2929
}, 'module', 'action', 'iconCls', 'rows']
3030
});

0 commit comments

Comments
 (0)