Skip to content

Commit 0d00239

Browse files
committed
2.3.8 release with security fixes
1 parent 6d2af80 commit 0d00239

File tree

8 files changed

+13
-12
lines changed

8 files changed

+13
-12
lines changed

SECURITY.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
Tiny values the work of security researchers in improving the security of technology products worldwide. We welcome researchers who wish to responsibly disclose vulnerabilities in our products or systems. Note that we do not offer any “bug bounty” program or any form of payment for disclosed vulnerabilities. If you would like to report a vulnerability, please email infosec@tiny.cloud.

js/jquery.plupload.queue/jquery.plupload.queue.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -223,7 +223,7 @@ used as it is.
223223

224224
fileList.append(
225225
'<li id="' + file.id + '">' +
226-
'<div class="plupload_file_name"><span>' + file.name + '</span></div>' +
226+
'<div class="plupload_file_name"><span>' + plupload.xmlEncode(file.name) + '</span></div>' +
227227
'<div class="plupload_file_action"><a href="#"></a></div>' +
228228
'<div class="plupload_file_status">' + file.percent + '%</div>' +
229229
'<div class="plupload_file_size">' + plupload.formatSize(file.size) + '</div>' +
@@ -306,7 +306,7 @@ used as it is.
306306

307307
// Rename file and glue extension back on
308308
file.name = targetInput.val() + ext;
309-
targetSpan.html(file.name);
309+
targetSpan.text(file.name);
310310
targetInput.blur();
311311
}
312312
});

js/jquery.plupload.queue/jquery.plupload.queue.min.js

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

js/jquery.ui.plupload/jquery.ui.plupload.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -491,7 +491,7 @@ $.widget("ui.plupload", {
491491
break;
492492
}
493493

494-
message += " <br /><i>" + details + "</i>";
494+
message += " <br /><i>" + plupload.xmlEncode(details) + "</i>";
495495

496496
self._trigger('error', null, { up: up, error: err } );
497497

@@ -1313,7 +1313,7 @@ $.widget("ui.plupload", {
13131313
// Rename file and glue extension back on
13141314
if (e.keyCode === 13) {
13151315
file.name = nameInput.val() + ext;
1316-
nameSpan.html(file.name);
1316+
nameSpan.text(file.name);
13171317
}
13181318
nameInput.blur();
13191319
}

js/jquery.ui.plupload/jquery.ui.plupload.min.js

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,8 +15,8 @@
1515
"Silverlight",
1616
"moxie"
1717
],
18-
"version": "2.3.7",
19-
"releaseDate": "2021-03-29",
18+
"version": "2.3.8",
19+
"releaseDate": "2021-11-15",
2020
"author": "Ephox",
2121
"contributors": [{
2222
"name": "Davit Barbakadze",

src/jquery.plupload.queue/jquery.plupload.queue.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -223,7 +223,7 @@ used as it is.
223223

224224
fileList.append(
225225
'<li id="' + file.id + '">' +
226-
'<div class="plupload_file_name"><span>' + file.name + '</span></div>' +
226+
'<div class="plupload_file_name"><span>' + plupload.xmlEncode(file.name) + '</span></div>' +
227227
'<div class="plupload_file_action"><a href="#"></a></div>' +
228228
'<div class="plupload_file_status">' + file.percent + '%</div>' +
229229
'<div class="plupload_file_size">' + plupload.formatSize(file.size) + '</div>' +
@@ -306,7 +306,7 @@ used as it is.
306306

307307
// Rename file and glue extension back on
308308
file.name = targetInput.val() + ext;
309-
targetSpan.html(file.name);
309+
targetSpan.text(file.name);
310310
targetInput.blur();
311311
}
312312
});

src/jquery.ui.plupload/jquery.ui.plupload.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -491,7 +491,7 @@ $.widget("ui.plupload", {
491491
break;
492492
}
493493

494-
message += " <br /><i>" + details + "</i>";
494+
message += " <br /><i>" + plupload.xmlEncode(details) + "</i>";
495495

496496
self._trigger('error', null, { up: up, error: err } );
497497

@@ -1313,7 +1313,7 @@ $.widget("ui.plupload", {
13131313
// Rename file and glue extension back on
13141314
if (e.keyCode === 13) {
13151315
file.name = nameInput.val() + ext;
1316-
nameSpan.html(file.name);
1316+
nameSpan.text(file.name);
13171317
}
13181318
nameInput.blur();
13191319
}

0 commit comments

Comments
 (0)