Explorar o código

Merge pull request #3137 from r0hanSH/fix_dom_xss

Fix DOM XSS
Hakim El Hattab %!s(int64=3) %!d(string=hai) anos
pai
achega
c47bf217be
Modificáronse 1 ficheiros con 4 adicións e 0 borrados
  1. 4 0
      plugin/notes/speaker-view.html

+ 4 - 0
plugin/notes/speaker-view.html

@@ -368,6 +368,10 @@
 
 
 				window.addEventListener( 'message', function( event ) {
 				window.addEventListener( 'message', function( event ) {
 
 
+					if (window.location.origin !== event.origin){
+						return;
+					}
+
 					clearTimeout( connectionTimeout );
 					clearTimeout( connectionTimeout );
 					connectionStatus.style.display = 'none';
 					connectionStatus.style.display = 'none';