From c127306b540cc0ee7cda9f7b14cd2c9bb47b99a1 Mon Sep 17 00:00:00 2001 From: Katrin Fischer Date: Wed, 16 Aug 2017 12:05:50 +0200 Subject: [PATCH] Bug 19125 - XSS - members.pl In preparation to test this patch: - Add a patron list named - Add a library named - Add a patron category named To test: - Access patron search page and do a search - Verify that the alerts added above are executed - Apply patch - Verify that no alerts are displayed Signed-off-by: Amit Gupta Signed-off-by: Marcel de Rooy Signed-off-by: Mason James --- koha-tmpl/intranet-tmpl/prog/en/includes/patron-search.inc | 2 +- koha-tmpl/intranet-tmpl/prog/en/includes/patron-toolbar.inc | 2 +- koha-tmpl/intranet-tmpl/prog/en/modules/members/member.tt | 6 +++--- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/koha-tmpl/intranet-tmpl/prog/en/includes/patron-search.inc b/koha-tmpl/intranet-tmpl/prog/en/includes/patron-search.inc index 41c67b8d5d..b8dac1859f 100644 --- a/koha-tmpl/intranet-tmpl/prog/en/includes/patron-search.inc +++ b/koha-tmpl/intranet-tmpl/prog/en/includes/patron-search.inc @@ -94,7 +94,7 @@ [% IF b.selected %] [% ELSE %] - + [% END %] [% END %] diff --git a/koha-tmpl/intranet-tmpl/prog/en/includes/patron-toolbar.inc b/koha-tmpl/intranet-tmpl/prog/en/includes/patron-toolbar.inc index 3b04aea250..284709246f 100644 --- a/koha-tmpl/intranet-tmpl/prog/en/includes/patron-toolbar.inc +++ b/koha-tmpl/intranet-tmpl/prog/en/includes/patron-toolbar.inc @@ -6,7 +6,7 @@
[% IF CAN_user_tools_manage_patron_lists %] diff --git a/koha-tmpl/intranet-tmpl/prog/en/modules/members/member.tt b/koha-tmpl/intranet-tmpl/prog/en/modules/members/member.tt index b597a8f9c0..ccb4561475 100644 --- a/koha-tmpl/intranet-tmpl/prog/en/modules/members/member.tt +++ b/koha-tmpl/intranet-tmpl/prog/en/modules/members/member.tt @@ -372,7 +372,7 @@ function filterByFirstLetterSurname(letter) { [% IF patron_lists %] [% FOREACH pl IN patron_lists %] - + [% END %] [% END %] @@ -496,9 +496,9 @@ function filterByFirstLetterSurname(letter) { [% FOREACH cat IN categories %] [% IF cat.selected %] - + [% ELSE %] - + [% END %] [% END %] -- 2.39.5