Bug 11322: fix XSS bug in purchase suggestions - OPAC
authorChris Cormack <chrisc@catalyst.net.nz>
Mon, 2 Dec 2013 22:46:24 +0000 (11:46 +1300)
committerGalen Charlton <gmc@esilibrary.com>
Tue, 3 Dec 2013 00:20:12 +0000 (00:20 +0000)
commit90f3b84def924dcc76719c01d75aa09241c92f8e
tree7069eb2b65ab57c8512e708411d20cde527d5b5e
parent368068c71597eaf61e4f9cc154002ea92dfd16c3
Bug 11322: fix XSS bug in purchase suggestions - OPAC

1/ Add a suggestion in the opac, with lots of html
2/ View that suggestion in the OPAC, note the html is rendering
3/ Apply the patch
4/ Test again, in prog and bootstrap, no more rendered html

Signed-off-by: David Cook <dcook@prosentient.com.au>

Works as described.

Signed-off-by: Katrin Fischer <Katrin.Fischer.83@web.de>
Signed-off-by: Galen Charlton <gmc@esilibrary.com>
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-suggestions.tt
koha-tmpl/opac-tmpl/prog/en/modules/opac-suggestions.tt