| @@ -5,11 +5,15 @@ | ||
| 5 | 5 | ?> |
| 6 | 6 | <style> |
| 7 | 7 | <?php |
| 8 | 8 | // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CSS is sanitized via fluentformSanitizeCSS() |
| 9 | - echo $generated_css; | |
| 9 | + echo fluentformSanitizeCSS($generated_css); | |
| 10 | + // SECURITY (FINDING-13): $submit_css interpolates the top-level submitButton colours raw | |
| 11 | + // (never covered by Updater::sanitizeCustomSubmit), so a background_color of | |
| 12 | + // "red}</style><script>..." would break out here. The standalone view already sanitizes; | |
| 13 | + // this inline view did not. fluentformSanitizeCSS() blanks any CSS containing a tag pattern. | |
| 10 | 14 | // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped -- CSS is sanitized via fluentformSanitizeCSS() |
| 11 | - echo $submit_css; | |
| 15 | + echo fluentformSanitizeCSS($submit_css); | |
| 12 | 16 | ?> |
| 13 | 17 | </style> |
| 14 | 18 | <div class="ffc_conv_wrapper ffc_inline_form"> |
| 15 | 19 | <div class="frm-fluent-form ff_conv_app fluent_form_<?php echo esc_attr($form_id); ?> ff_conv_app_frame ff_conv_app_<?php echo esc_attr($form_id); ?> ffc_media_hide_mob_<?php echo esc_attr($design['hide_media_on_mobile']); ?>" data-form_id="<?php echo esc_attr($form_id) ?>"> |