Bug 13609: Cross Site Scripting problem in authority search result list paging
authorKatrin Fischer <katrin.fischer@bsz-bw.de>
Thu, 22 Jan 2015 13:41:09 +0000 (14:41 +0100)
committerTomas Cohen Arazi <tomascohen@gmail.com>
Thu, 22 Jan 2015 19:39:14 +0000 (16:39 -0300)
commitc667b9ddbf42f9729d8f4035c7e872d5e980a5e9
treea62c426cb13c01c0bf6d225307499a83e38e7784
parentda6ee1c469c63f6d28dd1302032a19596eb7cd57
Bug 13609: Cross Site Scripting problem in authority search result list paging

To test:
- Use an installation a reasonable amount of authorities, so that you can
  have a search result list with more than one page
- Activate OpacAuthorities
- Create an OPAC link like shown below, verify that an alert is shown
- Apply patch
- Refresh the page and no alert should appear
- Verify the paging still works correctly for 'numbers' and 'arrows'

URL:
.../cgi-bin/koha/opac-authorities-home.pl?and_or=and&marclist=match&op=do_search&operator=contains&orderby=HeadingAsc2"><script>prompt(987898)</script>

Signed-off-by: Jonathan Druart <jonathan.druart@biblibre.com>
Signed-off-by: Tomas Cohen Arazi <tomascohen@gmail.com>
Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-authoritiessearchresultlist.tt