From 2e282e1f8b4b2eba831f0954303153363e895484 Mon Sep 17 00:00:00 2001 From: Claude Date: Tue, 18 Aug 2026 21:56:14 +0300 Subject: [PATCH] security(compliance-hub): HTML-encode the application name in the export-history action cell Backport of #7961 to release.24.05. The export/purge history model builds each row's action cell as an HTML string rendered with v-html. Other values in that string are API-encoded, but the application name is read from countlyGlobal, whose values are raw at runtime. Encode it with countlyCommon.encodeHtml so it renders as text. Only the application name needed encoding; the display is unchanged. Co-Authored-By: Claude Opus 4.8 --- CHANGELOG.md | 3 +++ .../frontend/public/javascripts/countly.models.js | 2 +- 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7703fab7885..e5672f804aa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,9 @@ Fixes: Enterprise Fixes: - [data-manager] Fixed editing an event whose key contains `&` creating undeletable duplicate rows in the events table +Security Fixes: +- [compliance-hub] The export/purge history table now HTML-encodes the application name before it is placed in the action cell, so an application name is shown as text rather than markup + ## Version 24.05.51 Fixes: diff --git a/plugins/compliance-hub/frontend/public/javascripts/countly.models.js b/plugins/compliance-hub/frontend/public/javascripts/countly.models.js index bd758822308..7ba4100c071 100644 --- a/plugins/compliance-hub/frontend/public/javascripts/countly.models.js +++ b/plugins/compliance-hub/frontend/public/javascripts/countly.models.js @@ -194,7 +194,7 @@ var ret = "

" + ((jQuery.i18n.map["systemlogs.action." + row.a]) ? jQuery.i18n.map["systemlogs.action." + row.a] : row.a) + "

"; if (typeof row.i === "object") { if (typeof row.i.app_id !== "undefined" && countlyGlobal.apps[row.i.app_id]) { - ret += "

" + jQuery.i18n.map["systemlogs.for-app"] + ": " + countlyGlobal.apps[row.i.app_id].name + "

"; + ret += "

" + jQuery.i18n.map["systemlogs.for-app"] + ": " + countlyCommon.encodeHtml(countlyGlobal.apps[row.i.app_id].name) + "

"; } if (typeof row.i.appuser_id !== "undefined") { ret += "

" + jQuery.i18n.map["systemlogs.for-appuser"] + ": " + row.i.appuser_id + "

";