From 79cd9e9fd460b7376ee06fe51eed1e3ed9392d81 Mon Sep 17 00:00:00 2001 From: Jonathan Druart Date: Tue, 2 Aug 2016 16:05:09 +0100 Subject: [PATCH] Bug 16800: Fix XSS in catalogue/*detail.tt - isbn Test plan: catalogue a bibliographic record with a isbn= Go on the detail pages. => Without this patch you will see the alert => With this patch, no more alert Signed-off-by: Chris Cormack Signed-off-by: Katrin Fischer Signed-off-by: Kyle M Hall --- koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/detail.tt | 2 +- koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/moredetail.tt | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/detail.tt b/koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/detail.tt index d53df31f4a..c33463d649 100644 --- a/koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/detail.tt +++ b/koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/detail.tt @@ -500,7 +500,7 @@ function verify_images() {
    [% IF ( MARCISBNS ) %] -
  • ISBN:
      [% FOREACH MARCISBN IN MARCISBNS %]
    • [% MARCISBN %]
    • [% END %]
  • +
  • ISBN:
      [% FOREACH MARCISBN IN MARCISBNS %]
    • [% MARCISBN | html %]
    • [% END %]
  • [% ELSE %] [% IF ( normalized_isbn ) %]
  • ISBN: [% normalized_isbn %]
  • diff --git a/koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/moredetail.tt b/koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/moredetail.tt index 2870d955ec..b04fd398ec 100644 --- a/koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/moredetail.tt +++ b/koha-tmpl/intranet-tmpl/prog/en/modules/catalogue/moredetail.tt @@ -41,7 +41,7 @@
  • Item type: [% itemtypename %] 
  • [% END %] [% IF ( rentalcharge ) %]
  • Rental charge:[% rentalcharge %] 
  • [% END %] -
  • ISBN: [% isbn %] 
  • +
  • ISBN: [% isbn | html %] 
  • Publisher:[% place %] [% publishercode |html %] [% publicationyear %] 
  • [% IF ( volumeddesc ) %]
  • Volume: [% volumeddesc %]
  • [% END %]
  • Physical details: [% pages %] [% illus %] [% size %] 
  • -- 2.20.1