]> git.koha-community.org Git - koha.git/commit
Bug 17114: Fix XSS in picture-upload.pl
authorJonathan Druart <jonathan.druart@bugs.koha-community.org>
Fri, 12 Aug 2016 09:42:28 +0000 (10:42 +0100)
committerJulian Maurice <julian.maurice@biblibre.com>
Fri, 16 Sep 2016 09:55:59 +0000 (11:55 +0200)
commite48dac0bf5b6705c82fac3df8041773bfce4084f
tree5204bd54a07faffdf427478f32677ef0d9776fbe
parentfe5b80d5633ab09d3994fac09dd5d9971931af0a
Bug 17114: Fix XSS in picture-upload.pl

To reproduce:
1/ cp your_image.jpg 'test<svg onload=alert(1)>.jpg'
2/ Use the upload picture tool to upload this file
=> Without this patch, the alert is show
=> With this patch, the filename is correctly displayed and no alert

Note that the cardnumber var was not escaped neither, it's now.

Signed-off-by: Colin Campbell <colin.campbell@ptfs-europe.com>
Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>
Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com>
(cherry picked from commit da03dbd458c59da0b9213efacd3425e89b453332)
Signed-off-by: Frédéric Demians <f.demians@tamil.fr>
(cherry picked from commit 0fba9c17c9154379430119646c3571f09d986948)
Signed-off-by: Julian Maurice <julian.maurice@biblibre.com>
koha-tmpl/intranet-tmpl/prog/en/modules/tools/picture-upload.tt