From f1ba6e97f4e171566f6785069ecfca627c132f25 Mon Sep 17 00:00:00 2001 From: Ananya Sen Date: Wed, 18 Jul 2012 09:10:54 -0700 Subject: removing iframes from pasted content to prevent frame injection attack Signed-off-by: Ananya Sen --- js/clipboard/external-apps-clipboard-agent.js | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/js/clipboard/external-apps-clipboard-agent.js b/js/clipboard/external-apps-clipboard-agent.js index 5a82314b..65410543 100644 --- a/js/clipboard/external-apps-clipboard-agent.js +++ b/js/clipboard/external-apps-clipboard-agent.js @@ -186,9 +186,10 @@ var ExternalAppsClipboardAgent = exports.ExternalAppsClipboardAgent = Montage.cr sanitize : { value: function(data){ data = data.replace(/\]+>/gi, ""); // Remove meta tags - data = data.replace(/\