Menu

#5305 XSS vulnerability when viewing Logfile

1.930
pending
nobody
xss (2)
7
2019-10-02
2019-09-12
No

XSS vulnerability when viewing Logfile, items in log file are not properly escaped.

1 Attachments

Discussion

  • Ilia

    Ilia - 2019-09-12

    Bud, hi.

    Thank you very much for reporting. Stripping HTML using jQuery is a joke. I fixed that.

    Could you please try it with the patched verion? You can install latest developemnt version in no time using theme configuration or clicking hotkey (when run as root) - Ctrl+Shift+Alt+Meta+U (PC) and Control+Shift+Option+Command+U (Mac).

    One more thing, could you attach or send me privately your log file?

     

    Last edit: Ilia 2019-09-12
  • Ilia

    Ilia - 2019-09-13

    Bud, any news on this one? :)

     
  • Ilia

    Ilia - 2019-09-21

    Bud, I would appreciate any feedback!

     
  • Bud Damyanov

    Bud Damyanov - 2019-10-01

    Hey there Ilia, I will try to update the version, later today I'll send you the logs in private message

     

    Last edit: Bud Damyanov 2019-10-01
  • Bud Damyanov

    Bud Damyanov - 2019-10-01

    Here is the error log.

     
  • Bud Damyanov

    Bud Damyanov - 2019-10-01

    I can confirm that the bug is no longer present in current version 19.39-2, thank you for your support.

     
  • Ilia

    Ilia - 2019-10-01

    Thanks for your log file.

    However, it's fixed only in version starting 19.40-beta1 + but 19.39-2 still has it!

     
  • Ilia

    Ilia - 2019-10-01
    • status: open --> pending
     
  • Bud Damyanov

    Bud Damyanov - 2019-10-02

    This is weird, because I no longer get JS execution when previewing the log file...

     

Log in to post a comment.

Auth0 Logo