From bd29b9ff5d74ac93c0e6778f52c1ad30965d0dcc Mon Sep 17 00:00:00 2001 From: Michele Romano <33063403+Mik317@users.noreply.github.com> Date: Fri, 31 Jul 2020 01:16:13 +0200 Subject: [PATCH] [FIX] XSS validating context and encoding HTML --- src/jquery.form.js | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/src/jquery.form.js b/src/jquery.form.js index 168d4b8b..72cc4945 100644 --- a/src/jquery.form.js +++ b/src/jquery.form.js @@ -262,6 +262,10 @@ var successArguments = arguments, fn = options.replaceTarget ? 'replaceWith' : 'html'; + // Validate `data` through `HTML encoding` when passed `data` is passed + // to `html()`, as suggested in https://github.com/jquery-form/form/issues/464 + fn == 'html' ? data = $.parseHTML($("