diff --git a/CHANGELOG.md b/CHANGELOG.md index 64fbf009..a094b831 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,7 @@ +## [Unrelease] +### Changed +- Se verifica una URL sacando la vulnerabilidade de injeción de HTML + ## [1.56.2] - 2023-07-10 ### Fixed - Se revierten cambios de LoyaltyCongrats para agilizar otros desarrollos diff --git a/Source/Components/Touchpoints/LiveImages/MLBusinessLiveImagesWebView.swift b/Source/Components/Touchpoints/LiveImages/MLBusinessLiveImagesWebView.swift index 317c6ad6..76db8584 100644 --- a/Source/Components/Touchpoints/LiveImages/MLBusinessLiveImagesWebView.swift +++ b/Source/Components/Touchpoints/LiveImages/MLBusinessLiveImagesWebView.swift @@ -50,6 +50,10 @@ class MLBusinessLiveImagesWebView: UIView { } func loadImage(from url: String) { + guard let urlString = URL(string: url) else { + return + } + let html = """