Project

General

Profile

Actions

Bug #72475

closed

XSS in belog module

Added by Oliver Hader about 8 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2015-12-30
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
6.2
PHP Version:
5.5
Tags:
Complexity:
Is Regression:
No
Sprint Focus:

Description

The belog module, accessible for admin users, is vulnerable for XSS.

Requirements

a) create a backend user having the name

te<b>st</b>

b) create a workspace record having the title
work<b>space</b>

PoC

  • switch to the created user
  • switch to the create workspace
  • modify or create any content
  • open the log at System>Log and see the unescaped contents of the user and workspace

Files

72475.png (19.3 KB) 72475.png Oliver Hader, 2015-12-30 13:23
Actions

Also available in: Atom PDF