]> git.koha-community.org Git - koha.git/commit
Bug 16597: Fix XSS in opac-shelves.pl
authorChris Cormack <chrisc@catalyst.net.nz>
Thu, 26 May 2016 09:06:18 +0000 (21:06 +1200)
committerJulian Maurice <julian.maurice@biblibre.com>
Thu, 16 Jun 2016 07:02:27 +0000 (09:02 +0200)
commit5d1f6b08cc7ef12975eb6637459204b9153de5a2
tree5f5c3f2d9fc9683338bb03da212c0cbb5ecf82c0
parentdd94d1bc4ca68d8466b4d7fb154c6714a7782b58
Bug 16597: Fix XSS in opac-shelves.pl

To test
1/ Hit /cgi-bin/koha/opac-shelves.pl?shelfnumber=5&category=1&op=edit_form&referer="><script>alert('XSS')</SCRIPT>
2/ Notice JS is executed
3/ Apply patch
4/ Notice it's fixed

This bug reported by

Alex Middleton at Dionach

Signed-off-by: Chris Cormack <chris@bigballofwax.co.nz>
Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>
Signed-off-by: Brendan Gallagher <brendan@bywatersolutions.com>
(cherry picked from commit 344033c32490df3e396ed530dcbf250086483371)
Signed-off-by: Julian Maurice <julian.maurice@biblibre.com>
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-shelves.tt