Bug 14423: XSS bugs in catalogue search
authorChris <chris@bigballofwax.co.nz>
Sun, 21 Jun 2015 09:01:32 +0000 (09:01 +0000)
committerTomas Cohen Arazi <tomascohen@theke.io>
Tue, 23 Jun 2015 13:12:18 +0000 (10:12 -0300)
commita5489d993615996e1e125e945870dce92c7d1c10
treef1c3eb40f97318330bb8a4a30be61c8658661fd3
parent91a8584aa845fb1695a46fe3b89197f7d1365d94
Bug 14423: XSS bugs in catalogue search

To test

1/ hit a url like http://localhost:8081/cgi-bin/koha/catalogue/search.pl?limit=%3Cscript%3Ealert%28%27oh%20noes%27%29%3C/script%3E
2/ Notice alert boxes
3/ Apply patch
4/ Reload url, no alerts
5/ Check search still works

Signed-off-by: Jonathan Druart <jonathan.druart@koha-community.org>
Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/results.tt