Jonathan Druart
1ea1504c30
Test plan: Hit /serials/serials-search.pl?ISSN_filter="%2F><script>alert('XSS')<%2Fscript>&searched=1 /serials/serials-search.pl?title_filter="%2F><script>alert('XSS')<%2Fscript>&searched=1 => Without this patch you will see the alert => With this patch, no more alert Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz> Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de> Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com> |
||
---|---|---|
.. | ||
js | ||
lib | ||
prog |