Bug 19611: Fix XSS Flaws in supplier.pl
authorAmit Gupta <amit.gupta@informaticsglobal.com>
Sun, 12 Nov 2017 15:44:41 +0000 (20:44 +0530)
committerFridolin Somers <fridolin.somers@biblibre.com>
Sat, 23 Dec 2017 09:58:12 +0000 (10:58 +0100)
commit22f485761915c43a04a3547806a936b567c39b85
tree9444c79f299f4e6680dfcddfbec0beb307deeeeb
parent3ade912a388e076ab7811e680dc43ece587cd964
Bug 19611: Fix XSS Flaws in supplier.pl

Test
1. Hit the page /cgi-bin/koha/acqui/supplier.pl?op=enter
2. Add a text in the field Name that contains java script
3. Save the page.
4. Notice js is execute
5. Apply patch and reload the js is escaped

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>

Signed-off-by: Josef Moravec <josef.moravec@gmail.com>

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>

Signed-off-by: Nick Clemens <nick@bywatersolutions.com>
(cherry picked from commit 99d327a5ea039b98f2bb19a3ef29431b33437cb7)
Signed-off-by: Fridolin Somers <fridolin.somers@biblibre.com>
koha-tmpl/intranet-tmpl/prog/en/modules/acqui/booksellers.tt
koha-tmpl/intranet-tmpl/prog/en/modules/acqui/supplier.tt