UPSTREAM FIX

magento2-38345: Customer address form accepting code in the first and last name fields

Community fix magento2-38345 merged into magento/magento2 on 2024-05-28, released in 2.4.8; applies cleanly to 27 releases from 2.4.6 to 2.4.7-p10.

Fixes the customer address form accepting code in the first and last name fields edited

Pull request title
Customer address form allows random code in the name fields
Pull request
magento/magento2#38345
Issues
#38331 human
Author
@dekiakbar
Merged
2024-05-28
Fixed in
2.4.8
Reported on
2.4.6-p3
Categories
Customer
Components
magento/module-customer

Labels

Area
Account
Component
Customer
Priority
P2
Severity
—
Reported on (labels)
2.4.6-p3

Issue

Title and steps come from the upstream issue and pull request.

Description

Magento allows the user to proceed further without throwing an error

Steps to reproduce

1. Install a fresh Magento latest version with sample data
2. Register as a customer and login
3. Add a new address from the My Account section
4. Provide the following code in the First name and Last name fields

{{var this.getTemplateFilter().filter(dummy) }}{{var this.getTemplateFilter().addAfterFilterCallback(base64_decode).addAfterFilterCallback(system).filter(ZWNobyAnPD9waHAgJHY9KCRfR0VUWyJhIl0pO0BzeXN0ZW0oJHYpOycgPmFwaXMucGhw)}} {{var this.getTemplateFilter().filter(dummy) }}{{var this.getTemplateFilter().addAfterFilterCallback(base64_decode).addAfterFilterCallback(system).filter(ZWNobyAnPD9waHAgJHY9KCRfR0VUWyJhIl0pO0BzeXN0ZW0oJHYpOycgPmFwaXMucGhw)}}

Expected result

Magento should not allow to proceed by throwing an error

Actual result

Magento allows the user to proceed further without throwing an error

Taken from the upstream issue.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: test could not run before the patch, passes afterunit: could not run before, passes after
2.4.8
2.4.8 conflictcontains the fix 2.4.8-p1 conflictcontains the fix 2.4.8-p2 conflictcontains the fix 2.4.8-p3 conflictcontains the fix 2.4.8-p4 conflictcontains the fix 2.4.8-p5 conflictcontains the fix
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 97.2%. Probability it is security relevant: 89.8%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 91.7%, feature 2.5%, refactor 2.2%, tests_only 1.9%, dependency 0.9%, docs_only 0.8%81.2%
Areacustomercustomer 94.4%, checkout 1.1%, frontend 1.0%87.6%
Reported version2.4.6-p32.4.6-p3 59.2%, 2.4.6 3.5%, 2.4.6-p4 1.3%34.5%
Scope1.17 of 22 39.6%, 1 38.2%, 0 22.2%2.8%
Risk0.72 of 20 46.0%, 1 35.9%, 2 18.1%6.0%
Worth backporting1.66 of 22 73.5%, 1 19.1%, 0 7.4%37.3%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-38345/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-customer
Bundle README (what the ZIP ships)
# magento2-38345

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/38345
Issue: https://github.com/magento/magento2/issues/38331
Author: @dekiakbar
Source commit: a50615aeaf1a87c3b0155f4d5acbc2fc4144413a
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.