Koha/koha-tmpl
Amit Gupta b90662073f Bug 19127: Fix Stored XSS in csv-profiles.pl
To Test
1. Hit the page /cgi-bin/koha/tools/csv-profiles.pl?op=add_form
2. Add a text in the field Profile name, Profile description
   and Profile MARC fields that contains js
3. Save the page.
4. Notice js is execute
5. Apply patch and reload, the js is escaped

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>

Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
2017-09-29 12:20:51 -03:00
..
intranet-tmpl Bug 19127: Fix Stored XSS in csv-profiles.pl 2017-09-29 12:20:51 -03:00
opac-tmpl Bug 19173: Make OPAC online payments pluggable 2017-09-19 14:15:52 -03:00
favicon.ico
index.html
intranet.html
opac.html