Bug 19611: Fix XSS Flaws in supplier.pl
authorAmit Gupta <amit.gupta@informaticsglobal.com>
Sun, 12 Nov 2017 15:44:41 +0000 (21:14 +0530)
committerNick Clemens <nick@bywatersolutions.com>
Thu, 21 Dec 2017 12:07:16 +0000 (12:07 +0000)
commit99d327a5ea039b98f2bb19a3ef29431b33437cb7
treef0abad883f1a43cf2f4c9305c40356c2f45812c7
parent33b0a26a5bf32de1ffead556269d8f8e27289521
Bug 19611: Fix XSS Flaws in supplier.pl

Test
1. Hit the page /cgi-bin/koha/acqui/supplier.pl?op=enter
2. Add a text in the field Name that contains java script
3. Save the page.
4. Notice js is execute
5. Apply patch and reload the js is escaped

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>
Signed-off-by: Josef Moravec <josef.moravec@gmail.com>
Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
Signed-off-by: Nick Clemens <nick@bywatersolutions.com>
koha-tmpl/intranet-tmpl/prog/en/modules/acqui/booksellers.tt
koha-tmpl/intranet-tmpl/prog/en/modules/acqui/supplier.tt