From b211b2be915b2bd1e6d1baea655717bb235afe82 Mon Sep 17 00:00:00 2001 From: Owen Leonard Date: Tue, 11 Aug 2020 15:22:33 +0000 Subject: [PATCH] Bug 26102: Prevent XSS when To.json is used: subscription-add.tt Test the process of adding a subscription, entering both a valid vendor ID and a non-existent vendor ID. The non-existent vendor ID should trigger a validation alert. Signed-off-by: Nick Clemens Signed-off-by: Katrin Fischer Signed-off-by: Fridolin Somers --- .../intranet-tmpl/prog/en/modules/serials/subscription-add.tt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/koha-tmpl/intranet-tmpl/prog/en/modules/serials/subscription-add.tt b/koha-tmpl/intranet-tmpl/prog/en/modules/serials/subscription-add.tt index 6c22b7cdd1..4e9f2362f5 100644 --- a/koha-tmpl/intranet-tmpl/prog/en/modules/serials/subscription-add.tt +++ b/koha-tmpl/intranet-tmpl/prog/en/modules/serials/subscription-add.tt @@ -585,7 +585,7 @@ fieldset.rows table { clear: none; margin: 0; } var MSG_MANA_NO_SUBSCRIPTION_FOUND = _("No subscription found on Mana Knowledge Base"); var MSG_MANA_SHARE_PATTERN = _("Please feel free to share your pattern with all others librarians once you are done"); - var BOOKSELLER_IDS = [% To.json( bookseller_ids ) || '[]' | $raw %]; + var BOOKSELLER_IDS = [% To.json( bookseller_ids ) || '[]' | html %]; [% Asset.js("js/subscription-add.js") | $raw %] [% Asset.js("js/showpredictionpattern.js") | $raw %] -- 2.39.5