| @@ -62,11 +62,14 @@ | ||
| 62 | 62 | }, |
| 63 | 63 | success: function (response) { |
| 64 | 64 | jQuery('.loader').fadeOut(); |
| 65 | 65 | jQuery('.loader-mask').delay(350).fadeOut('slow'); |
| 66 | + // SECURITY FIX: Server now returns sanitized HTML (wp_kses output). | |
| 67 | + // Do NOT run htmlspecialchars_decode() on conversation data before .html(); | |
| 68 | + // that decode-then-inject pattern was the DOM XSS sink. | |
| 66 | 69 | let htmlString = response.conversation; |
| 67 | 70 | let doc = '<div class="session-details-sction-modal">' ; |
| 68 | - doc += htmlspecialchars_decode(htmlString); | |
| 71 | + doc += htmlString; | |
| 69 | 72 | doc += '</div>'; |
| 70 | 73 | if (response.email) { |
| 71 | 74 | doc += '<div class="email-reply-container">' + |
| 72 | 75 | '<p class="email-reply-meta">Reply via <strong>Email to:</strong> ' + response.email + ' <strong>From:</strong> <input type="email" id="reply_from_email" class="form-control" value="' + ( response.email_from ? '' + response.email_from : '' ) + '"></p>' + |
| @@ -132,11 +135,14 @@ | ||
| 132 | 135 | success: function (response) { |
| 133 | 136 | if (typeof Swal !== 'undefined') { |
| 134 | 137 | Swal.close(); |
| 135 | 138 | } |
| 139 | + // SECURITY FIX: Server now returns sanitized HTML (wp_kses output). | |
| 140 | + // Do NOT run htmlspecialchars_decode() on conversation data before .html(); | |
| 141 | + // that decode-then-inject pattern was the DOM XSS sink. | |
| 136 | 142 | let htmlString = response.conversation; |
| 137 | 143 | let doc = '<div class="session-details-sction-modal">' ; |
| 138 | - doc += htmlspecialchars_decode(htmlString); | |
| 144 | + doc += htmlString; | |
| 139 | 145 | doc += '</div>'; |
| 140 | 146 | if (response.email) { |
| 141 | 147 | var replyEmail = response.email || ''; |
| 142 | 148 | var replyEmailText = jQuery('<div>').text(replyEmail).html(); |