]> git.koha-community.org Git - koha.git/commit
Bug 19034: XSS Flaws in Z39.50/SRU servers administration
authorAmit Gupta <amit.gupta@informaticsglobal.com>
Fri, 4 Aug 2017 05:11:49 +0000 (10:41 +0530)
committerMason James <mtj@kohaaloha.com>
Thu, 24 Aug 2017 05:57:03 +0000 (17:57 +1200)
commitcfd67c694e48e119c68e7bb9504d371d3049e689
tree52491c32fe1c9188b7fcaa0ab28d2a440bd8645e
parent8a14d5233879a9f0cc296aaf94a94a98eb345caa
Bug 19034: XSS Flaws in Z39.50/SRU servers administration

1. Hit /cgi-bin/koha/admin/z3950servers.pl
2. Enter <IFRAME SRC="javascript:alert('XSS');"></IFRAME> search Z39.50/SRU servers box.
3. Notice the iframe is executed.
4. Apply patch.
5. Reload page, and enter iframe again on search Z39.50/SRU servers box.
6. Notice it is no longer executed.

Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
Signed-off-by: Mason James <mtj@kohaaloha.com>
koha-tmpl/intranet-tmpl/prog/en/modules/admin/z3950servers.tt