From b94811ec09262141665ad660cf7ba0d8e67cfc82 Mon Sep 17 00:00:00 2001 From: morning-star <26325820+Sight-wcg@users.noreply.github.com> Date: Mon, 22 Apr 2024 17:21:45 +0800 Subject: [PATCH] =?UTF-8?q?fix(form-select):=20=E4=BF=AE=E5=A4=8D=20XSS=20?= =?UTF-8?q?=E6=BC=8F=E6=B4=9E=20(#1813)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- src/modules/form.js | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/src/modules/form.js b/src/modules/form.js index 345bc0c0..bd92ab55 100644 --- a/src/modules/form.js +++ b/src/modules/form.js @@ -654,14 +654,13 @@ layui.define(['lay', 'layer', 'util'], function(exports){ if(hasEquals){ dl.children('.' + CREATE_OPTION).remove(); }else{ - // 和初始渲染保持行为一致 - var textVal = $('
' + value +'
').text(); var createOptionElem = dl.children('.' + CREATE_OPTION); if(createOptionElem[0]){ - createOptionElem.attr('lay-value', value); - createOptionElem.text(textVal); + createOptionElem.attr('lay-value', value).html(util.escape(value)); }else{ - dl.append('
' + textVal + '
'); + var ddElem = $('
'); + ddElem.addClass(CREATE_OPTION).attr('lay-value', value).html(util.escape(value)); + dl.append(ddElem); } } }else{ @@ -722,7 +721,9 @@ layui.define(['lay', 'layer', 'util'], function(exports){ if(isCreatable && othis.hasClass(CREATE_OPTION)){ othis.removeClass(CREATE_OPTION); - select.append(''); + var optionElem = $('