PluginProbe
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder / 6.2.15
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder v6.2.15
6.2.15 6.2.14 6.2.13 6.2.12 6.2.10 6.2.11 6.2.9 6.2.8 6.2.7 6.2.6 6.2.5 6.2.4 6.2.3 6.2.2 3.6.22 3.6.31 3.6.40 3.6.41 3.6.42 3.6.50 3.6.51 3.6.60 3.6.61 3.6.62 3.6.64 All 197 releases
← All changes | app/Services/FormBuilder/Components/DateTime.php +14 -8 6.2.11 → 6.2.15 View file →
@@ -55,9 +55,12 @@
55 55 $id = $data['attributes']['id'];
56 56
57 57 $ariaLabel = esc_html__(' Use arrow keys to navigate dates. Press enter to select a date.', 'fluentform');
58 58 $label = ArrayHelper::get($data, 'settings.label');
59 - $elMarkup = "<input aria-label='" . $label . $ariaLabel . "' aria-haspopup='dialog' data-type-datepicker data-format='" . esc_attr($dateFormat) . "' " . $atts . " aria-invalid='false' aria-required={$ariaRequired}>"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $atts is escaped before being passed in.
59 + // SECURITY (FINDING-12): esc_attr the settings.label before interpolating it into the
60 + // single-quoted aria-label; the save-time wp_kses does not encode quotes, so an unescaped
61 + // label allows an attribute breakout (stored XSS).
62 + $elMarkup = "<input aria-label='" . esc_attr($label) . $ariaLabel . "' aria-haspopup='dialog' data-type-datepicker data-format='" . esc_attr($dateFormat) . "' " . $atts . " aria-invalid='false' aria-required={$ariaRequired}>"; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- $atts is escaped before being passed in.
60 63 $config = $this->getDateFormatConfigJSON($data['settings'], $form);
61 64 $customConfig = $this->getCustomConfig($data['settings'], $form);
62 65 $this->loadToFooter($config, $customConfig, $form, $id);
63 66 $html = $this->buildElementMarkup($elMarkup, $data, $form);
@@ -137,16 +140,19 @@
137 140 }
138 141
139 142 public function getCustomConfig($settings, $form = null)
140 143 {
141 - $customConfigObject = fluentform_sanitize_json_object(
142 - (string) ArrayHelper::get($settings, 'date_config')
143 - );
144 + $customConfigObject = trim((string) ArrayHelper::get($settings, 'date_config'));
144 145
145 - // Emitted JS is rebuilt from validated data tokens (ints only) — the raw setting never reaches the script sink.
146 - $customConfigObject = fluentform_date_config_to_js($customConfigObject);
147 -
148 - $customConfigObject = '' !== $customConfigObject ? $customConfigObject : '{}';
146 + if (
147 + !$customConfigObject ||
148 + '{' !== substr($customConfigObject, 0, 1) ||
149 + '}' !== substr($customConfigObject, -1)
150 + ) {
151 + $customConfigObject = '{}';
152 + } else {
153 + $customConfigObject = str_ireplace('</script', '<\\/script', $customConfigObject);
154 + }
149 155
150 156 return apply_filters('fluentform/date_time_custom_config', $customConfigObject, $settings, $form);
151 157 }
152 158