Bug 14360: Unescaped variable causes alert pop-up
authorAleisha <aleishaamohia@hotmail.com>
Tue, 9 Jun 2015 02:02:55 +0000 (02:02 +0000)
committerChris Cormack <chrisc@catalyst.net.nz>
Thu, 11 Jun 2015 20:10:59 +0000 (08:10 +1200)
commitcab96a3c8c4cf1827bf3350107e82da75b8b8856
tree1a23a27e298fdd63e294bb7e537400b1b2a5a10c
parentff0281d40ad9bcff563a595082b051dd4304ffc2
Bug 14360: Unescaped variable causes alert pop-up

To test:

1) Create a list in the OPAC, name it: <script>alert('Hello');</script>
2) Delete the list
3) Confirm deletion
4) See the alert say 'Hello'
5) Apply patch
6) Recreate list with same name
7) Delete list
8) Confirm deletion and alert no longer pops up

Signed-off-by: Katrin Fischer <Katrin.Fischer.83@web.de>
Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com>
Signed-off-by: Tomas Cohen Arazi <tomascohen@gmail.com>
(cherry picked from commit 9bef8f8738492564af7da78cba841366c70ada3c)
Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-shelves.tt