From 81f0969426a4845108ca7c4a8b3cec6337bb56b4 Mon Sep 17 00:00:00 2001 From: Carlos Rodrigues Date: Tue, 20 Aug 2019 16:47:00 -0300 Subject: [PATCH] Encode checkbox value to prevent XSS attack (#584) --- src/Former/Traits/Checkable.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/Former/Traits/Checkable.php b/src/Former/Traits/Checkable.php index d38f69c3..ed4e7f7d 100644 --- a/src/Former/Traits/Checkable.php +++ b/src/Former/Traits/Checkable.php @@ -362,7 +362,7 @@ protected function createCheckable($item, $fallbackValue = 1) } // Create field - $field = Input::create($this->checkable, $name, $value, $attributes); + $field = Input::create($this->checkable, $name, Helpers::encode($value), $attributes); if ($this->isChecked($item, $value)) { $field->checked('checked'); }