Koha/koha-tmpl
Amit Gupta ec86950780 Bug 19086: Fix Stored XSS in subscription-add.pl
To Test
1. Hit the page /cgi-bin/koha/serials/subscription-add.pl
2. Add a text in the field Public note and Nonpublic note
   that contains js (Internalnotes, notes)
2. Save the page.
3. Notice js is execute
4. Apply patch and reload, the js is escaped

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>

Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
2017-09-29 12:20:45 -03:00
..
intranet-tmpl Bug 19086: Fix Stored XSS in subscription-add.pl 2017-09-29 12:20:45 -03:00
opac-tmpl Bug 19173: Make OPAC online payments pluggable 2017-09-19 14:15:52 -03:00
favicon.ico
index.html
intranet.html
opac.html