https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=39882
--- Comment #28 from David Cook <[email protected]> --- (In reply to David Cook from comment #27) > Comment on attachment 204565 [details] [review] > Bug 39882: Add ability to mask phone numbers on memberentry.pl > > Review of attachment 204565 [details] [review]: > ----------------------------------------------------------------- > > ::: koha-tmpl/intranet-tmpl/prog/en/modules/members/memberentrygen.tt > @@ +1648,5 @@ > > + const pattern = "[% Koha.Preference('PhoneMaskPattern') | $raw %]"; > > + const fields = "[% Koha.Preference('PhoneMaskFields') | $raw %]"; > > + > > + if (pattern && fields) { > > + const mask = [[% Koha.Preference('PhoneMaskPattern') | $raw > > %]]; > > All these "[% Koha.Preference('PhoneMaskFields') | $raw %]" and "[% > Koha.Preference('PhoneMaskPattern') | $raw %]"lines are XSS vulnerabilities > that could lead to account takeover. Even if you were using CSP, the > Javascript being generated is "trusted", so a malicious payload would still > execute. > > While technically this code is meeting the JS19 coding guideline ( > https://wiki.koha-community.org/wiki/Coding_Guidelines#JS19:_Avoid_Template:: > Toolkit_tags_in_script_tags ), that guideline is currently incomplete, and > changes will be coming in the future. > > I'll have to take a look at the proposed patterns to see what would be the > appropriate filter instead of $raw... At a glance, I think you should be able to switch to using the "html" filter instead of $raw, and the double quote enclosed preferences should be OK from there, but that last one that doesn't have quotes is a problem. If that one needs to contain a JSON data structure, then it needs to first be parsed as JSON, escaped using a "json" filter, and then subbed into that line. -- You are receiving this mail because: You are watching all bug changes. _______________________________________________ Koha-bugs mailing list -- [email protected] To unsubscribe send an email to [email protected] website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
