]> git.koha-community.org Git - koha.git/commit
Bug 19319: Reflected XSS Vulnerability in opac-MARCdetail.pl
authorKyle M Hall <kyle@bywatersolutions.com>
Thu, 14 Sep 2017 15:52:08 +0000 (11:52 -0400)
committerNick Clemens <nick@bywatersolutions.com>
Thu, 21 Dec 2017 12:07:05 +0000 (12:07 +0000)
commit617e87c59d0b270d424aa4f1977e3e95c019e0b5
treec0fe98e93ed2387e9e5aa9ec45f32cb268e2833b
parent9b141bcd3dbeebd91d4df20205f57bbc564cbb32
Bug 19319: Reflected XSS Vulnerability in opac-MARCdetail.pl

Try going to this URL on your site: /cgi-bin/koha/opac-MARCdetail.pl?biblionumber=2"><TEST>

Test Plan:
1) Go to /cgi-bin/koha/opac-MARCdetail.pl?biblionumber=2"><TEST>
2) Note <TEST> is embedded all over the html
3) Apply this patch
4) Refresh the page, note the injection is gone!
5) run koha qa test tools

Signed-off-by: Mark Tompsett <mtompset@hotmail.com>
Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>
Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
Signed-off-by: Nick Clemens <nick@bywatersolutions.com>
koha-tmpl/opac-tmpl/bootstrap/en/includes/opac-detail-sidebar.inc
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-ISBDdetail.tt
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-MARCdetail.tt
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-detail.tt
opac/opac-ISBDdetail.pl
opac/opac-MARCdetail.pl
opac/opac-detail.pl