Main Koha release repository https://koha-community.org
Find a file
Jonathan Druart 12b4c83f5a Bug 17021: Fix XSS in circ/returns.pl
Test plan:
Enter the following in the barcode input:
<script>alert('XSS')</script>

=> Without this patch you will see the alert
=> With this patch, no more alert

Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>

Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com>
2016-08-10 13:18:54 +00:00
acqui Bug 16737 - Error when deleting EDIFACT message 2016-06-24 12:04:03 +00:00
admin Bug 6906 - show 'Borrower has previously issued... 2016-07-08 13:40:08 +00:00
api/v1 Bug 17041: Fix missing properties in patron.json 2016-08-05 06:08:12 +00:00
authorities Bug 16154: CGI->multi_param - Force scalar context 2016-04-26 23:16:43 +00:00
basket Bug 15451: Koha::CsvProfiles - Remove the residue 2016-07-22 17:18:36 +00:00
C4 Bug 7441 - search results showing wrong branch? 2016-08-10 13:14:19 +00:00
catalogue Bug 17029: Fix XSS in catalogue/*detail.pl 2016-08-10 13:15:50 +00:00
cataloguing Bug 14793: New cataloguing plugin unimarc_field_225a_bis 2016-07-22 17:27:36 +00:00
circ Bug 16849: Move IsDebarred to Koha::Patron->is_debarred 2016-07-15 18:08:14 +00:00
course_reserves Bug 16154: CGI->multi_param - Force scalar context 2016-04-26 23:16:43 +00:00
debian Bug 17062 - debian/control.in update: change maintainer 2016-08-08 14:32:00 +00:00
docs Bug 7143 : More new devs 2016-07-22 17:14:08 +00:00
errors Bug 15288: Error pages: Code duplication removal and better translatability 2016-01-27 05:57:34 +00:00
etc Bug 6499: [QA Follow-up] Trivial adjustments 2016-08-09 10:13:11 +00:00
install_misc Bug 16770: Remove 2 other occurrences of libmemoize-memcached-perl 2016-06-24 14:05:56 +00:00
installer Bug 7441 - search results showing wrong branch? 2016-08-10 13:14:19 +00:00
Koha Bug 17069: Koha::Patron::Category->store must default checkprevcheckout to 'inherit' 2016-08-10 13:12:34 +00:00
koha-tmpl Bug 17021: Fix XSS in circ/returns.pl 2016-08-10 13:18:54 +00:00
labels Bug 16154: CGI->multi_param - Assign a list 2016-04-26 23:16:43 +00:00
members Bug 16847: Remove C4::Members::GetTitles 2016-07-22 17:23:42 +00:00
misc Bug 16830: (followup) Remove weird character from warning in rebuild_zebra.pl 2016-08-04 19:41:42 +00:00
offline_circ Bug 15764: Fix timestamp sent by KOCT 2016-02-23 20:53:18 +00:00
opac Bug 16878: Fix XSS in opac-memberentry 2016-08-04 19:22:00 +00:00
OpenILS
patron_lists Bug 16154: CGI->multi_param - Force scalar context 2016-04-26 23:16:43 +00:00
patroncards Bug 14138: Patroncard: Warn user if PDF creation fails 2016-07-15 15:00:56 +00:00
plugins
reports Bug 16760: fix Circulation Statistics wizard under Plack 2016-07-08 12:48:27 +00:00
reserve Bug 17028: Fix XSS in reserve/request.pl 2016-08-04 18:12:05 +00:00
reviews
rotating_collections
serials Bug 15451: Koha::CsvProfiles - Remove the residue 2016-07-22 17:18:36 +00:00
services
skel
sms Bug 15258: Fix Perl scripts declaring unused variables 2015-12-30 17:24:45 -07:00
suggestion Bug 16154: CGI->multi_param - Declare a list 2016-04-26 23:16:42 +00:00
svc Bug 16508: Updating a syspref requires parameters_remaining_permissions 2016-06-06 17:33:18 +00:00
t Bug 17069: Koha::Patron::Category->store must default checkprevcheckout to 'inherit' 2016-08-10 13:12:34 +00:00
tags Bug 16154: CGI->multi_param - Assign a list 2016-04-26 23:16:43 +00:00
test
tmp/modified_authorities
tools Bug 15451: Better error handling 2016-07-22 17:18:37 +00:00
virtualshelves Bug 15451: (followup) fix filename extension for csv file 2016-07-22 17:18:37 +00:00
xt Bug 16174: (QA followup) Fix remaining tests 2016-04-01 19:11:33 +00:00
.editorconfig Bug 12545: Add EditorConfig.org file to the source tree 2014-08-22 11:07:45 -03:00
.htaccess
.mailmap
about.pl Bug 12721 - Syspref StatisticsFields: Warning on About page and text change in System preferences 2016-04-29 02:48:30 +00:00
changelanguage.pl
edithelp.pl Bug 16447: Remove occurrence of the borrow permission which does no longer exist 2016-05-05 21:28:14 +00:00
fix-perl-path.PL
help.pl Bug 16724: Fix link to the online documentation links 2016-06-24 12:00:42 +00:00
INSTALL
install-CPAN.pl
INSTALL.debian
INSTALL.fedora7 Bug 13642 - Remove MARC::Crosswalk::DublinCore from Koha 2016-01-27 06:23:08 +00:00
INSTALL.opensuse
INSTALL.ubuntu
Koha.pm Bug 16573 - DBRev 16.06.00.012 2016-08-01 09:54:30 +00:00
koha_perl_deps.pl
kohaversion.pl
LICENSE
mainpage.pl Bug 15548: Move new patron related code to Patron* 2016-03-03 14:38:26 -07:00
Makefile.PL Bug 17044: Fix wrong destination for 'api' directory 2016-08-05 04:32:36 +00:00
MANIFEST.SKIP
README
README.md Bug 15465 [QA Followup] - Update wording, switch logo, add links 2016-02-24 04:02:26 +00:00
README.robots
rewrite-config.PL Bug 16222: (QA followup) Add /api dir for the API 2016-04-20 21:18:36 +00:00

Koha is a free software integrated library system (ILS).

Koha is distributed under the GNU GPL version 3 or later.

Note: This is a synced mirror of the official Koha repo.

Note: Koha does not accept pull requests from git hosting sites.

Note: This project has its own bug tracker, to report a bug or submit a patch visit http://bugs.koha-comminity.org.

For guidelines on submitting patches for Koha please visit https://wiki.koha-community.org/wiki/SubmitingAPatch

The developers handbook can be found at https://wiki.koha-community.org/wiki/Developer_handbook

http://koha-community.org/

Koha Logo