Bug 16599: Fix XSS in opac-shareshelf.pl
authorJonathan Druart <jonathan.druart@bugs.koha-community.org>
Thu, 26 May 2016 11:03:55 +0000 (12:03 +0100)
committerChris Cormack <chrisc@catalyst.net.nz>
Tue, 21 Jun 2016 20:43:49 +0000 (08:43 +1200)
commit76844ae98a9fa577c53bfc3ff5fb28c92c44ff62
tree1800569b15d68d3c1a0a2f408ba9e10a18051b45
parent476f55d6b9df4da3abfd61b25422418f8c9bac29
Bug 16599: Fix XSS in opac-shareshelf.pl

Test plan:
- Create a list with the name "<script>alert(1)</script>"
- On the shelf list, click on share
=> Without this patch you will see the JS alert
=> With this patch applied you won't see it

Reported by Kaybee at Dionach

Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>

Signed-off-by: Brendan Gallagher <brendan@bywatersolutions.com>
(cherry picked from commit a44a930c076fceca0f7193f488e187d9849f89b6)
Signed-off-by: Julian Maurice <julian.maurice@biblibre.com>
(cherry picked from commit 858e3b2043e0eb1ce5bb9a6c36b3b87afb69ae22)
Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-shareshelf.tt