Koha/koha-tmpl/intranet-tmpl/prog/en/modules/labels
Amit Gupta c57d0b71c7 Bug 19050 - XSS Flaws in Quick spine label creator
1. Hit /cgi-bin/koha/labels/spinelabel-home.pl
2. Enter <IFRAME SRC="javascript:alert('XSS');"></IFRAME> barcode text box.
3. Notice the iframe is executed
4. Apply patch
5. Reload page, and enter iframe again on barcode text box.
6. Notice it is no longer executed

Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>

Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
2017-08-29 12:00:37 -03:00
..
label-bib-search.tt
label-edit-batch.tt Bug 16239: Update templates 2017-01-13 14:41:22 +00:00
label-edit-layout.tt
label-edit-profile.tt
label-edit-template.tt
label-home.tt
label-manage.tt Bug 16239: Update templates 2017-01-13 14:41:22 +00:00
label-print.tt
result.tt Bug 16239: Update templates 2017-01-13 14:41:22 +00:00
search.tt
spinelabel-home.tt
spinelabel-print.tt Bug 19050 - XSS Flaws in Quick spine label creator 2017-08-29 12:00:37 -03:00