Bug 19051 - XSS Flaws in Batch item deletion page
1. Hit /cgi-bin/koha/tools/batchMod.pl?del=1 2. Enter <IFRAME SRC="javascript:alert('XSS');"></IFRAME> in the Barcode list (one barcode per line) text area. 3. Notice the iframe is executed. 4. Apply patch. 5. Reload page, and enter iframe again on Barcode list (one barcode per line) text area. 6. Notice it is no longer executed. 7. Fixes for both barcode and itemnumber. Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz> Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl> Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
This commit is contained in:
parent
92d58c60b0
commit
9f19d3d44c
1 changed files with 1 additions and 1 deletions
|
@ -58,7 +58,7 @@ $(document).ready(function(){
|
|||
</thead>
|
||||
<tbody>
|
||||
[% FOREACH notfoundbarcode IN notfoundbarcodes %]
|
||||
<tr><td>[% notfoundbarcode.barcode %]</td></tr>
|
||||
<tr><td>[% notfoundbarcode.barcode |html %]</td></tr>
|
||||
[% END %]
|
||||
</tbody>
|
||||
</table>
|
||||
|
|
Loading…
Reference in a new issue