Bug 19078 - XSS Flaws in System preferences
authorAmit Gupta <amit.gupta@informaticsglobal.com>
Thu, 10 Aug 2017 16:21:38 +0000 (21:51 +0530)
committerJonathan Druart <jonathan.druart@bugs.koha-community.org>
Tue, 29 Aug 2017 15:00:37 +0000 (12:00 -0300)
commitee3bfd5d69f8f649c74e58385b8180faade875d0
treee4817fa26858f1b28f5ea8b9a389bd868efe555c
parentf94162564ad57ac9747d3967ba6671d982545dbc
Bug 19078 - XSS Flaws in System preferences

1. Hit /cgi-bin/koha/admin/preferences.pl
2. Enter <script>alert('amit')</script> in search system preferences box.
3. Notice the java script is executed.
4. Apply patch.
5. Reload page, and enter <script>alert('amit')</script> in search system preferences box.
6. Notice it is no longer executed.

Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>
Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
koha-tmpl/intranet-tmpl/prog/en/modules/admin/preferences.tt