Skip to content

[bot] Merge 25.7 to 25.11#715

Open
github-actions[bot] wants to merge 2 commits into
release25.11-SNAPSHOTfrom
25.11_fb_bot_merge_25.7
Open

[bot] Merge 25.7 to 25.11#715
github-actions[bot] wants to merge 2 commits into
release25.11-SNAPSHOTfrom
25.11_fb_bot_merge_25.7

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Generated automatically.
Merging changes from: 50c1dd8
Approve all matching PRs simultaneously.
Approval will trigger automatic merge.
Verify all PRs before approving: https://internal.labkey.com/Scrumtime/Backlog/harvest-gitOpenPullRequests.view?branch=25.11_fb_bot_merge_25.7

labkey-martyp and others added 2 commits June 22, 2026 13:43
## Rationale

BirthDataSource and ArrivalDataSource concatenated a data-controlled
column value (the gender lookup display value and the sourceFacility
value, respectively) directly into the clinical-history HTML without
escaping. That HTML is serialized to the history row's html property and
rendered unescaped in the EHR client, so a crafted value persisted and
executed as stored XSS when a user viewed the animal's clinical history.

## Related Pull Requests

None.

## Changes

- Route both values through the base-class safeAppend helper, which
HTML-escapes via PageFlowUtil.filter, matching every other nirc_ehr data
source.
- Drop the now-redundant manual hasColumn/null guards and the now-unused
FieldKey import.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants