1
0
mirror of https://github.com/bitwarden/browser synced 2025-12-16 16:23:44 +00:00

Fix #1020 - XSS via innerHTML property (#1022)

This commit is contained in:
Chad Scharf
2021-06-09 15:58:07 -04:00
committed by GitHub
parent fd328eef2a
commit fd683e9d71
2 changed files with 3 additions and 3 deletions

View File

@@ -104,7 +104,7 @@ async function initWebAuthn(obj: any) {
function error(message: string) {
const el = document.getElementById('msg');
resetMsgBox(el);
el.innerHTML = message;
el.textContent = message;
el.classList.add('alert');
el.classList.add('alert-danger');
}
@@ -114,7 +114,7 @@ function success(message: string) {
const el = document.getElementById('msg');
resetMsgBox(el);
el.innerHTML = message;
el.textContent = message;
el.classList.add('alert');
el.classList.add('alert-success');
}