Project

General

Profile

Actions

Bug #19838

closed

XSS vulnerability in workspace module

Added by Marcus Krause almost 16 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Must have
Assignee:
Category:
Workspaces
Target version:
-
Start date:
2009-01-16
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
4.0
PHP Version:
5.2
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

references TYPO3 Security Team OTRS issue #2008111310000065

Versions:
4.0 up to trunk (4.0, 4.1, 4.2, trunk)

Problem:
In typo3/mod/user/ws/wsol_preview.php parameter msg is echoed without sanitizing it beforhand.

Solution:
Wrap msg by hsc.

Provided by TYPO3 Security Team
(issue imported from #M10159)


Files

10159.diff (512 Bytes) 10159.diff Administrator Admin, 2009-01-16 03:39
Actions

Also available in: Atom PDF