Details
-
Bug
-
Status: Closed
-
Could
-
Resolution: Fixed
-
OpenMRS 1.9.0
-
None
Description
It's possible to put inject some Javascrip into forms on the location pages:
To reproduce:
1. Goto admin/locations/location.form and create new location (<script>alert(1)</script> as name).
2. Load this form, script is ran from Parent Location dropdown box.
admin/locations/locationTag.list - name, desc parameters
admin/locations/hierarchy.list - previously stored location name parameter.
Originally reported by Kevin Jacobs