PluginProbe
Tagembed: Social Media Feeds and Customer Reviews Widget / 8.0
Tagembed: Social Media Feeds and Customer Reviews Widget v8.0
7.9 8.0 7.8 7.5 7.6 7.7 7.4 trunk 3.10 3.9 4.0 4.1 4.2 4.3 4.4 4.5 4.6 4.7 4.8 4.9 5.0 5.1 5.2 5.3 5.4 All 45 releases
← All changes | assets/js/toast.js +13 -2 4.4 → 8.0 View file →
@@ -42,11 +42,22 @@
42 42 if (options.hasOwnProperty("duration")) {
43 43 this.duration = options.duration;
44 44 }
45 45 /*create toast*/
46 + /* The message is rendered as text only. No markup is built from it, so there is
47 + nothing for an attacker to break out of. */
46 48 let toastDiv = document.createElement("div");
47 - let elemHTML = '<span class="__tagembed__faicon"><i class="fas ' + this.icon + '" aria-hidden="true"></i></span><span class="__tagembed__btnmsg">' + this.message + '</span>';
48 - toastDiv.innerHTML = elemHTML;
49 + let toastIconSpan = document.createElement("span");
50 + toastIconSpan.className = "__tagembed__faicon";
51 + let toastIcon = document.createElement("i");
52 + toastIcon.className = "fas " + this.icon;
53 + toastIcon.setAttribute("aria-hidden", "true");
54 + toastIconSpan.appendChild(toastIcon);
55 + let toastMessageSpan = document.createElement("span");
56 + toastMessageSpan.className = "__tagembed__btnmsg";
57 + toastMessageSpan.textContent = (this.message === undefined || this.message === null) ? "" : String(this.message);
58 + toastDiv.appendChild(toastIconSpan);
59 + toastDiv.appendChild(toastMessageSpan);
49 60 toastDiv.className = this.type;
50 61 let toastParentDiv = document.createElement("div");
51 62 toastParentDiv.setAttribute('id', this.id);
52 63 toastParentDiv.className = this.className + " " + this.position;