Bug 19611: Fix XSS Flaws in supplier.pl
authorAmit Gupta <amit.gupta@informaticsglobal.com>
Sun, 12 Nov 2017 15:44:41 +0000 (20:44 +0530)
committerChris Cormack <chrisc@catalyst.net.nz>
Wed, 20 Dec 2017 23:53:48 +0000 (12:53 +1300)
commitfaeb759a86e4f89b060aae59eac46caaf70b1b15
treeb704c494357f94d3b7e69fd9434cfa5b341f2dfd
parent8e7e2e52c2d30ea98f7de7ff3d67943c63a195f3
Bug 19611: Fix XSS Flaws in supplier.pl

Test
1. Hit the page /cgi-bin/koha/acqui/supplier.pl?op=enter
2. Add a text in the field Name that contains java script
3. Save the page.
4. Notice js is execute
5. Apply patch and reload the js is escaped

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>

Signed-off-by: Josef Moravec <josef.moravec@gmail.com>

Signed-off-by: Jonathan Druart <jonathan.druart@bugs.koha-community.org>
koha-tmpl/intranet-tmpl/prog/en/modules/acqui/booksellers.tt
koha-tmpl/intranet-tmpl/prog/en/modules/acqui/supplier.tt