]> git.koha-community.org Git - koha.git/commit
Bug 14418 : XSS flaw in opac-shelves.pl
authorChris Cormack <chrisc@catalyst.net.nz>
Thu, 18 Jun 2015 23:30:22 +0000 (11:30 +1200)
committerLiz Rea <wizzyrea@gmail.com>
Sat, 20 Jun 2015 00:52:13 +0000 (12:52 +1200)
commit358e8e889d8a02d55210d353cd01bbf35d1ddc15
tree248cb5aac46733e5d2ab4b2b3d8a3ee659e4441b
parent611df7517a2f1fa58c6780463ff56253d908a23d
Bug 14418 : XSS flaw in opac-shelves.pl

To test:
1/ Create a list and add at least one item to it
2/ Hit a url like http://192.168.2.18/cgi-bin/koha/opac-shelves.pl?viewshelf=7&sort=author&direction=%22%3E%3Cscript%3Ealert%28%27oh%20noes%27%29%3C/script%3E
  Where the shelf id is the number of the list you created, notice the js is executed
3/ Apply the patch
4/ Reload the page notice the js is now escaped

Signed-off-by: Jonathan Druart <jonathan.druart@koha-community.org>
Signed-off-by: Katrin Fischer <katrin.fischer@bsz-bw.de>
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-shelves.tt