]> git.koha-community.org Git - koha.git/commit
Bug 19108 - Stored XSS in oai_sets.pl
authorAmit Gupta <amit.gupta@informaticsglobal.com>
Tue, 15 Aug 2017 08:03:57 +0000 (13:33 +0530)
committerMason James <mtj@kohaaloha.com>
Wed, 20 Sep 2017 03:03:18 +0000 (15:03 +1200)
commit75ca6a17ad080246197ec6664ad19a96785cfbcd
tree351ff9bb98b56743424ab424ef8329dc12474806
parent5a58f35afc6935f714e4724f098af447107e2043
Bug 19108 - Stored XSS in oai_sets.pl

To Test
1. Hit the page /cgi-bin/koha/admin/oai_sets.pl
2. Click on New set
3. Add a text in the field setSpec, setName that contains js
4. Save the page.
5. Notice js is execute
6. Apply patch and reload, the js is escaped

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>
Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>
Signed-off-by: Mason James <mtj@kohaaloha.com>
koha-tmpl/intranet-tmpl/prog/en/modules/admin/oai_set_mappings.tt
koha-tmpl/intranet-tmpl/prog/en/modules/admin/oai_sets.tt