Loading
fix: #3347810 Authenticated stored XSS via custom jQuery selector
The "Custom jQuery selector for control field" setting accepted arbitrary text with no validation or sanitization. jQuery treats a string starting with "<" as markup to construct rather than a selector to query, so a stored value like "<img src=x onerror=alert('xss')>" would execute for every visitor of the field configuration form.
Reject such values in ConditionalFieldEditForm::validateForm(), fall back to the automatically generated selector in ConditionalFieldsFormHelper::getSelector() as defense in depth, and add an update hook to clear any selector already stored this way.
Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com
Closes #3347810