Skip to content

Commit 09381a2

Browse files
DevDev
Dev
authored and
Dev
committed
Fixed jquery-ujs vulnerbility issue
1 parent 83b041b commit 09381a2

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

src/rails.js

+2-2
Original file line numberDiff line numberDiff line change
@@ -218,9 +218,9 @@
218218
target = link.attr('target'),
219219
csrfToken = rails.csrfToken(),
220220
csrfParam = rails.csrfParam(),
221-
form = $('<form method="post" action="' + href + '"></form>'),
221+
form = $('<form method="post"></form>'),
222222
metadataInput = '<input name="_method" value="' + method + '" type="hidden" />';
223-
223+
form.attr('action', href);
224224
if (csrfParam !== undefined && csrfToken !== undefined && !rails.isCrossDomain(href)) {
225225
metadataInput += '<input name="' + csrfParam + '" value="' + csrfToken + '" type="hidden" />';
226226
}

0 commit comments

Comments
 (0)