Project

General

Profile

Actions

Bug #29179

closed

Scheduler: Description is not escaped

Added by Georg Ringer about 13 years ago. Updated about 6 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2011-08-23
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
4.6
PHP Version:
5.3
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

Description is not escaped properly

Patch is attached.


Files

scheduler_xss.diff (1.09 KB) scheduler_xss.diff Patch Georg Ringer, 2011-08-23 07:23
Actions #1

Updated by Steffen Gebert about 13 years ago

I tend to solve this as a normal issue ("Description is not escaped"), as it requires admin permissions. While installing 3rd-party extensions, you always have to trust the authors.

Actions #2

Updated by Georg Ringer about 13 years ago

-1 for that because an extension author is not a trustable person.

Actions #3

Updated by Steffen Gebert about 13 years ago

Extension authors can send your whole database back home or create backdoors or whatever..!

Actions #4

Updated by Helmut Hummel about 13 years ago

I agree with Steffen here.

It would be clearly visible in TER and EM that this extension tries to do some weird things (and AFAIK TER and EM is secure in this regard).

Actions #5

Updated by Georg Ringer about 13 years ago

  • Subject changed from XSS in Scheduler to Scheduler: Description is not escaped
Actions #6

Updated by Marcus Krause about 13 years ago

  • Project changed from 1716 to TYPO3 Core

Only admins can exploit this vulnerability
-> Ticket visibility changed to public

Actions #7

Updated by Georg Ringer about 13 years ago

  • Status changed from Accepted to Under Review
Actions #8

Updated by Georg Ringer about 13 years ago

  • Status changed from Under Review to Accepted
Actions #9

Updated by Gerrit Code Review about 11 years ago

  • Status changed from Accepted to Under Review

Patch set 1 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/25132

Actions #10

Updated by Gerrit Code Review about 11 years ago

Patch set 2 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/25132

Actions #11

Updated by Gerrit Code Review about 11 years ago

Patch set 1 for branch TYPO3_6-1 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/25214

Actions #12

Updated by Gerrit Code Review about 11 years ago

Patch set 1 for branch TYPO3_6-0 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/25215

Actions #13

Updated by Gerrit Code Review about 11 years ago

Patch set 1 for branch TYPO3_4-7 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/25218

Actions #14

Updated by Tomita Militaru about 11 years ago

  • Status changed from Under Review to Resolved
  • % Done changed from 80 to 100
Actions #15

Updated by Gerrit Code Review about 11 years ago

  • Status changed from Resolved to Under Review

Patch set 1 for branch TYPO3_4-5 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/25231

Actions #16

Updated by Stefan Neufeind about 11 years ago

  • Status changed from Under Review to Resolved
Actions #17

Updated by Benni Mack about 6 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF