]> git.koha-community.org Git - koha.git/commit
Bug 19054 - XSS Flaws in Report - Top Most-circulated items
authorAmit Gupta <amit.gupta@informaticsglobal.com>
Mon, 7 Aug 2017 17:04:05 +0000 (22:34 +0530)
committerFridolin Somers <fridolin.somers@biblibre.com>
Wed, 23 Aug 2017 14:54:07 +0000 (16:54 +0200)
commit1c5b315787c5714b2453f9b1ec9eb66ae6aa51b3
tree1dc64ed6e7630208fb1b672bfcdf668652fc41b1
parent24fb60d714e5c6dc3ad3dec1295b871e196cfa98
Bug 19054 - XSS Flaws in Report - Top Most-circulated items

1. Hit /cgi-bin/koha/reports/cat_issues_top.pl
2. Enter <IFRAME SRC="javascript:alert('XSS');"></IFRAME> in Callnumber, Day, Month, Year search box.
3. Notice the iframe is executed.
4. Apply patch.
5. Reload page, and enter iframe again on Callnumber, Day, Month, Year search box.
6. Notice it is no longer executed.

Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>
Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
(cherry picked from commit 755a1fb372b29443b7d128c4c710f7a7ed63f189)
Signed-off-by: Fridolin Somers <fridolin.somers@biblibre.com>
koha-tmpl/intranet-tmpl/prog/en/modules/reports/cat_issues_top.tt