60983cfeee
This is a partial, perhaps temporary fix. "<", ">", and "&" characters in patron comments (AKA reviews) are converted to "<", ">", and "&" to avoid certain attacks, e.g., a user entering a <script> tag in a comment. A more permanent fix should scrub all (or perhaps just unsafe) tags from submitted comments entirely. Signed-off-by: Joshua Ferraro <jmf@liblime.com>
37 lines
927 B
Cheetah
37 lines
927 B
Cheetah
<!-- TMPL_INCLUDE name="doc-head-open.inc" --><!-- TMPL_IF NAME="LibraryNameTitle" --><!-- TMPL_VAR NAME="LibraryNameTitle" --><!-- TMPL_ELSE -->Koha Online<!-- /TMPL_IF --> Catalog ›
|
|
<!-- TMPL_INCLUDE NAME="doc-head-close.inc" -->
|
|
</head>
|
|
<body>
|
|
|
|
<!-- TMPL_INCLUDE name="masthead.inc" -->
|
|
|
|
<div id="doc3" class="yui-t1">
|
|
<div id="bd">
|
|
<div id="yui-main">
|
|
<div class="yui-b"><div class="yui-g">
|
|
|
|
<table>
|
|
<!--TMPL_LOOP NAME="reviews"-->
|
|
<tr>
|
|
<th>
|
|
<b><!--TMPL_VAR NAME="title"--></b>
|
|
</th>
|
|
</tr>
|
|
<tr>
|
|
<td>
|
|
<!--TMPL_VAR NAME="review" ESCAPE="HTML"-->
|
|
<p><!--TMPL_VAR NAME="datereviewed"--></p>
|
|
</td>
|
|
</tr>
|
|
<!--/TMPL_LOOP-->
|
|
</table>
|
|
|
|
</div>
|
|
</div>
|
|
</div>
|
|
<div class="yui-b">
|
|
<!--TMPL_INCLUDE NAME="navigation.inc" -->
|
|
<!-- TMPL_INCLUDE name="usermenu.inc" -->
|
|
</div>
|
|
</div>
|
|
<!-- TMPL_INCLUDE NAME="opac-bottom.inc" -->
|