Bug #72475

XSS in belog module

Added by Oliver Hader over 5 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2015-12-30
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
6.2
PHP Version:
5.5
Tags:
Complexity:
Is Regression:
No
Sprint Focus:

Description

The belog module, accessible for admin users, is vulnerable for XSS.

Requirements

a) create a backend user having the name

te<b>st</b>

b) create a workspace record having the title
work<b>space</b>

PoC

  • switch to the created user
  • switch to the create workspace
  • modify or create any content
  • open the log at System>Log and see the unescaped contents of the user and workspace

Files

72475.png (19.3 KB) 72475.png Oliver Hader, 2015-12-30 13:23
#1

Updated by Oliver Hader over 5 years ago

#2

Updated by Gerrit Code Review over 5 years ago

  • Status changed from New to Under Review

Patch set 1 for branch master of project Teams/Security/TYPO3v4-Core has been pushed to the review server.
It is available at https://review.typo3.org/45502

#3

Updated by Helmut Hummel over 5 years ago

  • Project changed from 1716 to TYPO3 Core
  • Category deleted (OW-A07: Cross Site Scripting)
  • Is Regression set to No

Users and Workspaces can only be created by admins, so it is fine to fix this in public

#4

Updated by Gerrit Code Review over 5 years ago

Patch set 1 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/45519

#5

Updated by Gerrit Code Review over 5 years ago

Patch set 1 for branch TYPO3_7-6 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/45522

#6

Updated by Oliver Hader over 5 years ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100
#7

Updated by Gerrit Code Review over 5 years ago

  • Status changed from Resolved to Under Review

Patch set 1 for branch TYPO3_6-2 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/45523

#8

Updated by Oliver Hader over 5 years ago

  • Status changed from Under Review to Resolved
#9

Updated by Benni Mack over 2 years ago

  • Status changed from Resolved to Closed

Also available in: Atom PDF