]> git.koha-community.org Git - koha.git/commit
Bug 13609: Cross Site Scripting problem in authority search result list paging
authorKatrin Fischer <katrin.fischer@bsz-bw.de>
Thu, 22 Jan 2015 13:41:09 +0000 (14:41 +0100)
committerChris Cormack <chrisc@catalyst.net.nz>
Thu, 22 Jan 2015 19:46:19 +0000 (08:46 +1300)
commitb8573a838bd0c3b7327d08c164f8ac8337109762
tree516b955590b6ac733909654c697e04d969abdb8f
parentc9500b2b08dfabba112bd374d6889fd25cbfa142
Bug 13609: Cross Site Scripting problem in authority search result list paging

To test:
- Use an installation a reasonable amount of authorities, so that you can
  have a search result list with more than one page
- Activate OpacAuthorities
- Create an OPAC link like shown below, verify that an alert is shown
- Apply patch
- Refresh the page and no alert should appear
- Verify the paging still works correctly for 'numbers' and 'arrows'

URL:
.../cgi-bin/koha/opac-authorities-home.pl?and_or=and&marclist=match&op=do_search&operator=contains&orderby=HeadingAsc2"><script>prompt(987898)</script>

Signed-off-by: Jonathan Druart <jonathan.druart@biblibre.com>
Signed-off-by: Tomas Cohen Arazi <tomascohen@gmail.com>
Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-authoritiessearchresultlist.tt