344033c324
To test 1/ Hit /cgi-bin/koha/opac-shelves.pl?shelfnumber=5&category=1&op=edit_form&referer="><script>alert('XSS')</SCRIPT> 2/ Notice JS is executed 3/ Apply patch 4/ Notice it's fixed This bug reported by Alex Middleton at Dionach Signed-off-by: Chris Cormack <chris@bigballofwax.co.nz> Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl> Signed-off-by: Brendan Gallagher <brendan@bywatersolutions.com> |
||
---|---|---|
.. | ||
bootstrap | ||
lib | ||
xslt |