8c3da35130
1. Hit /cgi-bin/koha/admin/currency.pl 2. Enter <IFRAME SRC="javascript:alert('XSS');"></IFRAME> search currencies box. 3. Notice the iframe is executed 4. Apply patch 5. Reload page, and enter iframe again on search currencies box. 6. Notice it is no longer executed Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io> Fixes the issue, follows common practice on the codebase. Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org> |
||
---|---|---|
.. | ||
intranet-tmpl | ||
opac-tmpl | ||
favicon.ico | ||
index.html | ||
intranet.html | ||
opac.html |