]> git.koha-community.org Git - koha.git/commit
Bug 14423 : XSS bug in lateorders
authorChris <chris@bigballofwax.co.nz>
Sun, 21 Jun 2015 08:18:20 +0000 (08:18 +0000)
committerLiz Rea <wizzyrea@gmail.com>
Tue, 23 Jun 2015 00:33:52 +0000 (12:33 +1200)
commit51cd2262c1548c8adaf213d1160d36dd3c1b1980
tree8bca5b90f0817be22fd554915cf2ffe343c501a5
parent794fb09fac40408e12504fb67337299e0b30abe9
Bug 14423 : XSS bug in lateorders

1/ hit a url like http://localhost:8081/cgi-bin/koha/acqui/lateorders.pl?delay=<script>alert('oh noes')</script>&estimateddeliverydatefrom
2/ Not you get an alert box
3/ Apply patch notice it is fixed
4/ Test functionality still works

Signed-off-by: Jonathan Druart <jonathan.druart@koha-community.org>
Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>
Signed-off-by: Liz Rea <wizzyrea@gmail.com>
koha-tmpl/intranet-tmpl/prog/en/modules/acqui/lateorders.tt