Bug 23451: Prevent XSS vulnerabilities in opac-imageviewer.pl
authorJonathan Druart <jonathan.druart@bugs.koha-community.org>
Wed, 14 Aug 2019 17:31:53 +0000 (13:31 -0400)
committerMartin Renvoize <martin.renvoize@ptfs-europe.com>
Wed, 27 Nov 2019 11:30:18 +0000 (11:30 +0000)
And certainly in other sripts as it is in opac-bottom.inc

Signed-off-by: Liz Rea <wizzyrea@gmail.com>
Signed-off-by: Nick Clemens <nick@bywatersolutions.com>
Signed-off-by: Martin Renvoize <martin.renvoize@ptfs-europe.com>
koha-tmpl/opac-tmpl/bootstrap/en/includes/opac-bottom.inc

index 1705cee..af060ff 100644 (file)
@@ -196,7 +196,7 @@ $.widget.bridge('uitooltip', $.ui.tooltip);
         return false;
     });
     $("#ulactioncontainer > ul > li > a.addtoshelf").on("click",function(){
-        Dopop('opac-addbybiblionumber.pl?biblionumber=[% biblionumber | html %]');
+        Dopop('opac-addbybiblionumber.pl?biblionumber=[% biblionumber | uri %]');
         return false;
     });
     $("body").on("click", ".addtocart", function(e){