]> git.koha-community.org Git - koha.git/commit
Bug 19125 - XSS - members.pl
authorKatrin Fischer <katrin.fischer.83@web.de>
Wed, 16 Aug 2017 10:05:50 +0000 (12:05 +0200)
committerKatrin Fischer <katrin.fischer.83@web.de>
Tue, 19 Sep 2017 21:00:22 +0000 (23:00 +0200)
commit5e405e8d5da74bfe5ffb6be40a7dbd9937017670
treee8365231be307d5675118a78f771ea45942ec46d
parent026ff59914398022364993ae7d568def17f1ba40
Bug 19125 - XSS - members.pl

In preparation to test this patch:
- Add a patron list named <script>alert("patron list")</script>
- Add a library named <script>alert("library")</script>
- Add a patron category named <script>alert("patron category")</script>

To test:
- Access patron search page and do a search
- Verify that the alerts added above are executed
- Apply patch
- Verify that no alerts are displayed

Signed-off-by: Amit Gupta <amit.gupta@informaticsglobal.com>
Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>
Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
(cherry picked from commit 849eaf73fc419b9a635a1ba4b69ef46a7544e55a)
Signed-off-by: Fridolin Somers <fridolin.somers@biblibre.com>
(cherry picked from commit 2b0bd9add5deae0ab5bee79ee75a6cb769d0dea8)
Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>
koha-tmpl/intranet-tmpl/prog/en/includes/html_helpers.inc
koha-tmpl/intranet-tmpl/prog/en/includes/patron-search.inc
koha-tmpl/intranet-tmpl/prog/en/includes/patron-toolbar.inc
koha-tmpl/intranet-tmpl/prog/en/modules/members/member.tt