1
0
Fork 0
mirror of https://github.com/YunoHost-Apps/rainloop_ynh.git synced 2024-09-03 20:16:18 +02:00
rainloop_ynh/sources/patches/rainloop_xss.patch
2022-04-24 23:04:14 +02:00

21 lines
804 B
Diff

--- rainloop/v/1.16.0/app/libraries/MailSo/Base/HtmlUtils.php 2022-04-24 22:35:36.000000000 +0200
+++ rainloop/v/1.16.0/app/libraries/MailSo/Base/HtmlUtils.php 2022-04-24 22:36:28.000000000 +0200
@@ -239,7 +239,8 @@
$oWrapHtml->setAttribute($sKey, $sValue);
}
- $oWrapDom = $oDom->createElement('div', '___xxx___');
+ $rand_str = base64_encode(random_bytes(32));
+ $oWrapDom = $oDom->createElement('div', $rand_str);
$oWrapDom->setAttribute('data-x-div-type', 'body');
foreach ($aBodylAttrs as $sKey => $sValue)
{
@@ -250,7 +251,7 @@
$sWrp = $oDom->saveHTML($oWrapHtml);
- $sResult = \str_replace('___xxx___', $sResult, $sWrp);
+ $sResult = \str_replace($rand_str, $sResult, $sWrp);
}
$sResult = \str_replace(\MailSo\Base\HtmlUtils::$KOS, ':', $sResult);