Bug 13425 - XSS in intranet facets - Patch for 3.18 and master
authorChris Cormack <chrisc@catalyst.net.nz>
Tue, 9 Dec 2014 23:47:30 +0000 (12:47 +1300)
committerMason James <mtj@kohaaloha.com>
Mon, 22 Dec 2014 16:58:52 +0000 (05:58 +1300)
commit73f4ace5dabba61500fa7bd25d7dadbf8b9da1ff
treeb47386273a427f22a12e07cf1c1b8bf88d2f860e
parentc5938127f499e8b4348e0306b2b5b22dfb868b00
Bug 13425 - XSS in intranet facets - Patch for 3.18 and master

To Test
1/ Craft a url like /cgi-bin/koha/catalogue/search.pl?q=smith&sort_by='"><script>prompt('Happy_Holidays')</script>

It is important it must return results and facets

2/ Notice the js is executed
3/ Apply the patch test again

Signed-off-by: Katrin Fischer <Katrin.Fischer.83@web.de>
No prompts, no functional regressions found.
Checked selecting and undoing facets, show more links and paging.
Signed-off-by: Mason James <mtj@kohaaloha.com>
koha-tmpl/intranet-tmpl/prog/en/includes/facets.inc
koha-tmpl/intranet-tmpl/prog/en/includes/page-numbers.inc