]> git.koha-community.org Git - koha.git/commit
Bug 37654: XSS in Batch record import for Citation column
authorPhil Ringnalda <phil@chetcolibrary.org>
Fri, 16 Aug 2024 02:57:42 +0000 (19:57 -0700)
committerwainuiwitikapark <wainuiwitikapark@catalyst.net.nz>
Wed, 11 Sep 2024 05:11:08 +0000 (05:11 +0000)
commita86de321f63fcd4b0c817848001163c647f3c2b6
tree8b665164db18cd35863dcb22ccfcb0b451d3153a
parentbc8238fcbda21c2e91a44a366a4a6415ea4296d4
Bug 37654: XSS in Batch record import for Citation column

Viewing a staged MARC record batch loads a DataTable from
/tools/batch_records_ajax.pl, and both batch_records_ajax.pl and the
DataTable just trust the author/title/isbn/issn to be free of HTML. They
shouldn't.

Test plan:
1. Without this patch applied, download attachment 170418, then Cataloging
   - Stage records for import - Select the downloaded file - Upload file -
   Stage for import
2. When the background job completes, View batch - you'll get three alert()s
   from the title, author, and ISSN, and the author and ISSN displayed huge
3. Apply patch, restart_all
4. Manage staged records - click HTMLescapingimporttestrecord.mrc - get zero
   alerts and no <h2> display

Sponsored-by: Chetco Community Public Library
Signed-off-by: David Cook <dcook@prosentient.com.au>
Signed-off-by: Martin Renvoize <martin.renvoize@ptfs-europe.com>
Signed-off-by: wainuiwitikapark <wainuiwitikapark@catalyst.net.nz>
koha-tmpl/intranet-tmpl/prog/en/modules/tools/manage-marc-import.tt