SM02383: Fix Incomplete string escaping or encoding #2570
+7
−7
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This PR addresses the CodeQL issues -
(https://liquid.microsoft.com/Web/Object/Read/ScanningToolWarnings/Requirements/CodeQL.SM02383#Zguide)
0feb1226-cbcf-46a8-a0d9-840b305b5fa9
309a78ad-f925-4a79-b174-e037408ae9a6
465b4852-7047-42f1-ab91-64db039708f8
7b2d7268-f410-4a06-959e-6c59f986b6f3
82234977-e8b5-4c11-aeeb-1410ac9bdef4
8fccf079-649e-43e6-8f1e-901457a2b767
c34a07d4-87ac-4f18-b13a-96c3d358998f
in the jquery.validate.js and DateTimeShortcuts.js files.
The identified issue was related to untrusted input, which is a common technique for preventing injection attacks.
Changes Made
Updated the jquery.validate.js file to properly escape and encode strings used in HTML attributes.
Updated the DateTimeShortcuts.js file to properly escape and encode strings used in HTML attributes.
Ensured that all instances of potentially unsafe string concatenation were replaced with properly escaped and encoded strings to avoid potential issues.