Koha/koha-tmpl/opac-tmpl/bootstrap/en/includes
Chris Cormack 5bdf4601df Bug 13425 - XSS in opac facets - Patch for master and 3.18
To Test
1/ Craft a url like /cgi-bin/koha/opac-search.pl?q=123&sort_by='"><script>prompt('Happy_Holidays')</script>&limit=123

It is important it must return results and facets

2/ Notice the js is executed
3/ Apply the patch test again

Signed-off-by: Mirko Tietgen <mirko@abunchofthings.net>
Popup is gone after applying the patch. Facet link still shows it but does not execute. It's gone after clicking the link.

Signed-off-by: Jonathan Druart <jonathan.druart@biblibre.com>
Signed-off-by: Tomas Cohen Arazi <tomascohen@gmail.com>
2014-12-11 12:10:32 -03:00
..
search
authorities-search-results.inc Bug 7442: (follow-up) apply change to Bootstrap theme 2014-05-05 01:30:45 +00:00
bodytag.inc Bug 12162 - Add class="branchcode" to body tag to make OPAC CSS-styleable per branch 2014-09-23 15:39:31 -03:00
calendar.inc
datatables.inc
date-format.inc Bug 11694: Improve handling of individual hold suspension in Bootstrap OPAC 2014-03-26 16:07:44 +00:00
doc-head-close.inc Bug 12220 - bootstrap not responsive on all devices 2014-07-03 10:38:21 -03:00
doc-head-open.inc Bug 13112 - Add name of template file in html comment for each '.tt' file. 2014-10-28 10:45:32 -03:00
item-status-schema-org.inc Bug 10626: (follow-up) replace use of KohaAuthorisedValues in the Bootstrap theme 2013-12-20 04:22:20 +00:00
item-status.inc Bug 9214 - Show damaged status in the OPAC for items which are not for loan 2014-11-11 15:13:03 -03:00
masthead-sco.inc
masthead.inc Bug 13144: Google transliteration does not work on bootstrap 2014-11-06 09:52:22 -03:00
navigation.inc
opac-authorities.inc
opac-bottom.inc Bug 13247 - Move opacuserjs at the end of opac-bottom.inc 2014-11-21 20:10:40 -03:00
opac-detail-sidebar.inc
opac-facets.inc Bug 13425 - XSS in opac facets - Patch for master and 3.18 2014-12-11 12:10:32 -03:00
opac-topissues.inc
page-numbers.inc
patron-title.inc
resort_form.inc
shelfbrowser.inc Bug 10309: (follow-up) Update for Bug 10856, improve shelf browser 2013-10-14 23:13:47 +00:00
subtypes_unimarc.inc Bug 11189: Rename "Print" label in UNIMARC advanced search 2013-11-08 16:48:42 +00:00
usermenu.inc Bug 10807: Add an authority search history for the OPAC - bootstrap 2014-05-05 02:37:57 +00:00