Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-4547

WebEngine cross-site scripting (XSS) issues

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 5.3 GA
    • Fix Version/s: 5.3.1
    • Component/s: WebEngine

      Description

      Some WebEngine templates don't properly escape their variables and thus are XSS vectors.

      no_site.ftl / no_blog.ftl:
      http://localhost:8080/nuxeo/site/sites/%3Cimg%20src=.%20onerror=alert(123)%20%3E

      list_sites.ftl:
      Use a blog name <img src=. onerror=alert(4) >

      error_create_page.ftl:
      ?

        Attachments

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: