fix: #3347810 Authenticated stored XSS via custom jQuery selector

The "Custom jQuery selector for control field" setting accepted arbitrary text with no validation or sanitization. jQuery treats a string starting with "<" as markup to construct rather than a selector to query, so a stored value like "<img src=x onerror=alert('xss')>" would execute for every visitor of the field configuration form.

Reject such values in ConditionalFieldEditForm::validateForm(), fall back to the automatically generated selector in ConditionalFieldsFormHelper::getSelector() as defense in depth, and add an update hook to clear any selector already stored this way.

Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com

Closes #3347810

Merge request reports

Loading
Loading