Bug 13425 - XSS in intranet facets - Patch for 3.18 and master
authorChris Cormack <chrisc@catalyst.net.nz>
Tue, 9 Dec 2014 23:47:30 +0000 (12:47 +1300)
committerTomas Cohen Arazi <tomascohen@gmail.com>
Sat, 27 Dec 2014 00:03:17 +0000 (21:03 -0300)
commit951f3346a25c7f2883f834398055c2413b8f9c9b
tree2a4bfe0246aa97bc9c557a4f441c700ad762137b
parent96eae74fc12defc8f81f073724fc663e5895b9a2
Bug 13425 - XSS in intranet facets - Patch for 3.18 and master

To Test
1/ Craft a url like /cgi-bin/koha/catalogue/search.pl?q=smith&sort_by='"><script>prompt('Happy_Holidays')</script>

It is important it must return results and facets

2/ Notice the js is executed
3/ Apply the patch test again

Signed-off-by: Katrin Fischer <Katrin.Fischer.83@web.de>
No prompts, no functional regressions found.
Checked selecting and undoing facets, show more links and paging.
Signed-off-by: Mason James <mtj@kohaaloha.com>

Signed-off-by: Tomas Cohen Arazi <tomascohen@gmail.com>
koha-tmpl/intranet-tmpl/prog/en/includes/facets.inc
koha-tmpl/intranet-tmpl/prog/en/includes/page-numbers.inc