]> git.koha-community.org Git - koha.git/commit
Bug 37654: XSS in Batch record import for Citation column
authorPhil Ringnalda <phil@chetcolibrary.org>
Fri, 16 Aug 2024 02:57:42 +0000 (19:57 -0700)
committerKatrin Fischer <katrin.fischer@bsz-bw.de>
Fri, 18 Oct 2024 10:07:46 +0000 (12:07 +0200)
commit8269ac3d1e234bebd0e93687c2139a084621929c
tree41d1f166241ef0f10157d82dc0ebc9f89b56c8db
parent05a3781cf1f0beec06db3706518da262da366a50
Bug 37654: XSS in Batch record import for Citation column

Viewing a staged MARC record batch loads a DataTable from
/tools/batch_records_ajax.pl, and both batch_records_ajax.pl and the
DataTable just trust the author/title/isbn/issn to be free of HTML. They
shouldn't.

Test plan:
1. Without this patch applied, download attachment 170418, then Cataloging
   - Stage records for import - Select the downloaded file - Upload file -
   Stage for import
2. When the background job completes, View batch - you'll get three alert()s
   from the title, author, and ISSN, and the author and ISSN displayed huge
3. Apply patch, restart_all
4. Manage staged records - click HTMLescapingimporttestrecord.mrc - get zero
   alerts and no <h2> display

Sponsored-by: Chetco Community Public Library
Signed-off-by: David Cook <dcook@prosentient.com.au>
Signed-off-by: Martin Renvoize <martin.renvoize@ptfs-europe.com>
Signed-off-by: Katrin Fischer <katrin.fischer@bsz-bw.de>
koha-tmpl/intranet-tmpl/prog/en/modules/tools/manage-marc-import.tt