Koha/koha-tmpl/intranet-tmpl
Amit Gupta 26864e9f6f Bug 19611: Fix XSS Flaws in supplier.pl
Test
1. Hit the page /cgi-bin/koha/acqui/supplier.pl?op=enter
2. Add a text in the field Name that contains java script
3. Save the page.
4. Notice js is execute
5. Apply patch and reload the js is escaped

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>

Signed-off-by: Josef Moravec <josef.moravec@gmail.com>

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
2018-01-09 16:02:00 -03:00
..
js
lib Bug 18810: Update Font Awesome to 4.7.0 2017-09-19 09:22:45 -03:00
prog Bug 19611: Fix XSS Flaws in supplier.pl 2018-01-09 16:02:00 -03:00