]> git.koha-community.org Git - koha.git/commit
Bug 11322: fix XSS bug in purchase suggestions - OPAC
authorChris Cormack <chrisc@catalyst.net.nz>
Mon, 2 Dec 2013 22:46:24 +0000 (11:46 +1300)
committerFridolin SOMERS <fridolin.somers@biblibre.com>
Fri, 13 Dec 2013 15:18:02 +0000 (16:18 +0100)
commit3eac4854a4309612c4bdd33eed5fbcb77d59d5ad
treea8bd4223fa87cfa9b6db333fafc5d8496ae337fd
parentf8278987e3e1bac23e968417728a821faa22aa57
Bug 11322: fix XSS bug in purchase suggestions - OPAC

1/ Add a suggestion in the opac, with lots of html
2/ View that suggestion in the OPAC, note the html is rendering
3/ Apply the patch
4/ Test again, in prog and bootstrap, no more rendered html

Signed-off-by: David Cook <dcook@prosentient.com.au>
Works as described.

Signed-off-by: Katrin Fischer <Katrin.Fischer.83@web.de>
Signed-off-by: Galen Charlton <gmc@esilibrary.com>
(cherry picked from commit 90f3b84def924dcc76719c01d75aa09241c92f8e)
Signed-off-by: Fridolin SOMERS <fridolin.somers@biblibre.com>
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-suggestions.tt
koha-tmpl/opac-tmpl/prog/en/modules/opac-suggestions.tt