From 22c44fc785e70d2e22ee5bd958ffa2b939d348ef Mon Sep 17 00:00:00 2001 From: Antony Chiu <antony@mobb.ai> Date: Wed, 17 Jul 2024 14:15:30 -0600 Subject: [PATCH 1/2] Update xss-example.js --- xss-example.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/xss-example.js b/xss-example.js index 24518b6..0cd3e61 100644 --- a/xss-example.js +++ b/xss-example.js @@ -1,5 +1,5 @@ var urlParams = new URLSearchParams(window.location.search); var name = urlParams.get('name'); -var unsafe_div = window.document.getElementById("vulnerable-div"); -unsafe_div.innerHTML = "Hello " + name; +var unsafe_div = window.document.getElementById("vulnerable-div"); +unsafe_div.innerHTML = "Hello " + name; From cbb4fe035a237760a271b1be07004ec0a7ff9bee Mon Sep 17 00:00:00 2001 From: Mobb autofixer <git@mobb.ai> Date: Thu, 18 Jul 2024 15:38:00 +0000 Subject: [PATCH 2/2] XSS fix by mobb-01755b8a-967a-4e3c-9115-ac5ae20033f6 --- xss-example.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/xss-example.js b/xss-example.js index 0cd3e61..b4adba3 100644 --- a/xss-example.js +++ b/xss-example.js @@ -2,4 +2,4 @@ var urlParams = new URLSearchParams(window.location.search); var name = urlParams.get('name'); var unsafe_div = window.document.getElementById("vulnerable-div"); -unsafe_div.innerHTML = "Hello " + name; +unsafe_div.textContent = "Hello " + name;