Actions
Bug #21333
closedSysext:lowlevel (function "DB>Full search") susceptible to XSS
Start date:
2009-10-22
Due date:
% Done:
0%
Estimated time:
TYPO3 Version:
4.2
PHP Version:
4.3
Tags:
Complexity:
Is Regression:
Sprint Focus:
Description
Sysext:lowlevel provides, amongst others, a function called "Full Search" that allows to query the database directly. Both sub-functions "raw search in all fields" and "advanced query" are susceptible to XSS as both modules fail to sanitize results.
Reported by Markus Krause
Security Team OTRS reference: 2009091210000033
(issue imported from #M12308)
Actions