Bug 16587 opac-sendshelf.pl is vulnerable to XSS
authorChris Cormack <chris@bigballofwax.co.nz>
Wed, 25 May 2016 14:06:28 +0000 (14:06 +0000)
committerChris Cormack <chrisc@catalyst.net.nz>
Wed, 3 Aug 2016 20:29:28 +0000 (08:29 +1200)
commitbe5d63eb8cb8543f698a0a41a88bf749c3a332e9
treeb2fd8e23749879cfe0b428d9d7d0194bad993c83
parentdbffc29ba7b55594189a923b48b6ae4086cfbe52
Bug 16587 opac-sendshelf.pl is vulnerable to XSS

To test
1/ Hit a url like
http://localhost:8080/cgi-bin/koha/opac-sendshelf.pl?email=%3Cscript%3Ealert(%27XSS%27)%3C%2Fscript%3Ezz%40zz&comment=tes&shelfid=4
2/ Notice you get a js alert
3/ Apply patch
4/ Notice the js is now escaped

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>

Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com>
koha-tmpl/opac-tmpl/bootstrap/en/modules/opac-sendshelfform.tt