PKP Bugzilla – Bug 7957
login source parameter needs escaping
Last modified: 2012-11-28 02:29:55 PST
The login page 'source' parameter lacks HTML removal.
strip html from source parameter https://github.com/pkp/omp/commit/f59a2f01516c7308997353f095b7d8b01848913e
strip html from source parameter https://github.com/pkp/pkp-lib/commit/a88fa9f045c6319111381305399044a5338a225c
strip html from source parameter https://github.com/pkp/omp/commit/da7f64ee71f3be71882b777a553e36e990df5744
Created attachment 3871 [details] Patch against OMP 1.0b
Created attachment 3872 [details] Patch against OJS pkp-lib 2.4.1
Hi Jason, a couple of suggestions for the patches here: - It will help users if we label them as applicable to lib-pkp - Additional patch/recommended patch listing for OJS 2.3.8
strip html from source parameter https://github.com/pkp/pkp-lib/commit/f203912651eff2f08c22243209dd30c73c97a002
Created attachment 3873 [details] Patch against OJS pkp-lib 2.3.8
Thanks, Michael. I've also started a new recommended patches page for OJS 2.3.8 with this patch.
We'll likely also need fixes for ocs-stable and ohs-stable ...
Created attachment 3874 [details] Patch against OCS pkp-lib 2.3.5
Created attachment 3875 [details] Patch against OHS pkp-lib 2.3.2
strip html from source parameter https://github.com/pkp/pkp-lib/commit/ae68891b3c31f0d0342f2c890d83436eee8cd866