[Koha-bugs] [Bug 13618] Prevent XSS in the Staff Client and the OPAC

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Thu Aug 20 23:52:19 CEST 2015


http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=13618

--- Comment #43 from Heather Braum <hbraum at nekls.org> ---
If it's any sys pref that deals with HTML/JS/CSS, here's a few more to check;
what about all the notices/slips templates? Do those need to be checked, too,
since they also use HTML/JS/CSS? 

Extra user-edited sys prefs: 
OpacSuppressionMessage
SCOUserCSS
SCOUserJS
SelfCheckHelpMessage
NoLoginInstructions

-- 
You are receiving this mail because:
You are watching all bug changes.


More information about the Koha-bugs mailing list