Bug 14360: Unescaped variable causes alert pop-up
authorAleisha <aleishaamohia@hotmail.com>
Tue, 9 Jun 2015 02:02:55 +0000 (02:02 +0000)
committerFridolin Somers <fridolin.somers@biblibre.com>
Tue, 23 Jun 2015 09:37:34 +0000 (11:37 +0200)
commitb5a0d0a72b2f7ee263184ec98a7ce1dd14b26315
tree74feea04bc261c60879a1e6ba6c7ac2ed2a4ffc2
parent47daa3e4a8f0e71585957ccffa1f7ed1ea62df6c
Bug 14360: Unescaped variable causes alert pop-up

To test:

1) Create a list in the OPAC, name it: <script>alert('Hello');</script>
2) Delete the list
3) Confirm deletion
4) See the alert say 'Hello'
5) Apply patch
6) Recreate list with same name
7) Delete list
8) Confirm deletion and alert no longer pops up

Signed-off-by: Katrin Fischer <Katrin.Fischer.83@web.de>
Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com>
Signed-off-by: Tomas Cohen Arazi <tomascohen@gmail.com>
(cherry picked from commit 9bef8f8738492564af7da78cba841366c70ada3c)
Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
(cherry picked from commit cab96a3c8c4cf1827bf3350107e82da75b8b8856)
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-shelves.tt