Skip to content

Commit 7faf048

Browse files
MAGETWO-67496: Escape product name for Display Actual Price
1 parent e47ac7d commit 7faf048

File tree

2 files changed

+3
-3
lines changed

2 files changed

+3
-3
lines changed

app/code/Magento/Msrp/view/base/templates/product/price/msrp.phtml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ if ($product->isSaleable()) {
5656
$data = ['addToCart' => [
5757
'origin'=> 'msrp',
5858
'popupId' => '#' . $popupId,
59-
'productName' => $product->getName(),
59+
'productName' => $block->escapeHtml($product->getName()),
6060
'productId' => $productId,
6161
'productIdInput' => 'input[type="hidden"][name="product"]',
6262
'realPrice' => $block->getRealPriceHtml(),

app/code/Magento/Msrp/view/frontend/templates/render/item/price_msrp_item.phtml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@
3838
<a href="javascript:void(0);"
3939
id="<?php /* @escapeNotVerified */ echo($popupId);?>"
4040
data-mage-init='{"addToCart":{"popupId": "#<?php /* @escapeNotVerified */ echo($popupId);?>",
41-
"productName": "<?php /* @escapeNotVerified */ echo $_product->getName() ?>",
41+
"productName": "<?php /* @escapeNotVerified */ echo $block->escapeJs($block->escapeHtml($_product->getName())) ?>",
4242
"realPrice": <?php /* @escapeNotVerified */ echo $block->getRealPriceJs($_product) ?>,
4343
"msrpPrice": "<?php /* @escapeNotVerified */ echo $_msrpPrice ?>",
4444
"priceElementId":"<?php /* @escapeNotVerified */ echo $priceElementId ?>",
@@ -51,5 +51,5 @@
5151
</span>
5252
<?php endif; ?>
5353
<?php $helpLinkId = 'msrp-help-' . $_id . $block->getRandomString(20); ?>
54-
<a href="javascript:void(0);" id="<?php /* @escapeNotVerified */ echo($helpLinkId);?>" data-mage-init='{"addToCart":{"helpLinkId": "#<?php /* @escapeNotVerified */ echo($helpLinkId);?>", "productName": "<?php /* @escapeNotVerified */ echo $_product->getName() ?>"}}' class="link tip"><?php /* @escapeNotVerified */ echo __("What's this?"); ?></a>
54+
<a href="javascript:void(0);" id="<?php /* @escapeNotVerified */ echo($helpLinkId);?>" data-mage-init='{"addToCart":{"helpLinkId": "#<?php /* @escapeNotVerified */ echo($helpLinkId);?>", "productName": "<?php /* @escapeNotVerified */ echo $block->escapeJs($block->escapeHtml($_product->getName())) ?>"}}' class="link tip"><?php /* @escapeNotVerified */ echo __("What's this?"); ?></a>
5555
</div>

0 commit comments

Comments
 (0)