From 21af7fb36aede6bd12487868d8463c2b14f8de69 Mon Sep 17 00:00:00 2001 From: Mark Mankins Date: Tue, 23 Apr 2019 13:21:59 -0400 Subject: [PATCH] HP Fortify re[ports the method _makeRange() in vis.js sends unvalidated data to a web browser. --- lib/shared/Configurator.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lib/shared/Configurator.js b/lib/shared/Configurator.js index 0f973430e..844b7a3e8 100644 --- a/lib/shared/Configurator.js +++ b/lib/shared/Configurator.js @@ -357,7 +357,7 @@ class Configurator { let input = document.createElement('input'); input.className = 'vis-configuration vis-config-rangeinput'; - input.value = range.value; + input.value = Number(range.value); var me = this; range.onchange = function () {input.value = this.value; me._update(Number(this.value), path);}; @@ -742,4 +742,4 @@ class Configurator { } -export default Configurator; \ No newline at end of file +export default Configurator;