Headline
CVE-2022-4733: fix aa1 · openemr/openemr@4565d8d
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.
@@ -50,21 +50,21 @@ {% if supportPhoneNumber %} <div class="phone d-flex justify-content-between"> <p>{{ “Support Phone Number"|xlt }}</p> <strong><a href="tel:{{ supportPhoneNumber|attr }}” target="_blank">{{ supportPhoneNumber|text }}</a></strong> <strong><a href="tel:{{ supportPhoneNumber|javascriptStringRemove|attr }}" target="_blank">{{ supportPhoneNumber|text }}</a></strong> </div> {% endif %}
{% if onlineSupportHref %} <div class="online-support d-flex justify-content-between"> <p>{{" Online Support"|xlt }}</p> <strong><a href="{{ onlineSupportHref|attr }}" target="_blank" rel="noopener">{{ onlineSupportHref|text }}</a></strong> <strong><a href="{{ onlineSupportHref|javascriptStringRemove|attr }}" target="_blank" rel="noopener">{{ onlineSupportHref|text }}</a></strong>
</div> {% endif %}
{% if userManualHref %} <div class="user-manual mt-3"> <a href="{{ userManualHref|attr }}" target="_blank" rel="opener" class="btn text-left btn-block btn-outline-secondary btn-lg"> <a href="{{ userManualHref|javascriptStringRemove|attr }}" target="_blank" rel="opener" class="btn text-left btn-block btn-outline-secondary btn-lg"> <i class="fa fa-fw fa-book fa-lg"></i> {{ "User Manual"|xlt }} </a> </div>