Bug 19612: Fix XSS in members/memberentry.pl
authorAmit Gupta <amit.gupta@informaticsglobal.com>
Mon, 13 Nov 2017 03:35:14 +0000 (08:35 +0530)
committerChris Cormack <chrisc@catalyst.net.nz>
Wed, 20 Dec 2017 23:57:10 +0000 (12:57 +1300)
commit7e0c35efa87d62fab2470ff897553a0a5b3121f5
treeaeecc1e17ff281deffc4527838b42733c1a501f2
parentfaeb759a86e4f89b060aae59eac46caaf70b1b15
Bug 19612: Fix XSS in members/memberentry.pl

To Test
1. Hit the page /cgi-bin/koha/members/memberentry.pl
2. Add a text in the field address, address2, city, state, country,
   zipcode, B_streetnumber, B_city, B_country, B_zipcode that contains js
3. Save the page.
4. Notice js is execute
5. Apply patch and reload, the js is escaped

Signed-off-by: Chris Cormack <chris@bigballofwax.co.nz>

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
koha-tmpl/intranet-tmpl/prog/en/includes/member-display-address-style-us.inc
koha-tmpl/intranet-tmpl/prog/en/includes/member-display-alt-address-style-us.inc
koha-tmpl/intranet-tmpl/prog/en/modules/members/moremember.tt