From e890ec6dd5136028ddbbbe46597d684d2977b5d5 Mon Sep 17 00:00:00 2001 From: uzairr Date: Fri, 21 Aug 2020 12:52:27 +0500 Subject: [PATCH] Fix xss in team member template PROD-2009 --- cms/templates/js/team-member.underscore | 30 ++++++++++++------------- 1 file changed, 15 insertions(+), 15 deletions(-) diff --git a/cms/templates/js/team-member.underscore b/cms/templates/js/team-member.underscore index afd20271b8..ec9fb356cf 100644 --- a/cms/templates/js/team-member.underscore +++ b/cms/templates/js/team-member.underscore @@ -1,11 +1,11 @@ -
  • +
  • - - <%= gettext("Current Role:") %> + + <%- gettext("Current Role:") %> - <%= roles[user.role] %> + <%- roles[user.role] %> <% if (is_current_user) { %> - <%= gettext("You!") %> + <%- gettext("You!") %> <% } %> @@ -13,11 +13,11 @@
  • -
  • aria-disabled="<%=!allow_delete%>"> - +
  • aria-disabled="<%-!allow_delete%>"> + - <%= viewHelpers.format(gettext("Delete the user, {username}"), {username:user.username}) %> + <%- viewHelpers.format(gettext("Delete the user, {username}"), {username:user.username}) %>