NOTE: If you are a developer, please use a private wiki based on foswiki/trunk on a daily base ...or use
trunk.foswiki.org to view this page for some minimal testing.
Use
Item11383 for general documentation changes for release 1.1.5. Use
Item9693 for docu changes for release 2.0.
Item405: ORIGURL used in template login used for example for reset password is an XSS attach vector
| Priority: |
CurrentState: |
AppliesTo: |
Component: |
WaitingFor: |
| Urgent |
Closed |
Engine |
|
Main.KennethLavrsen |
ORIGURL used in template login used for example for reset password is an XSS attach vector
http://somedomain.com/foswiki/bin/login/System/ResetPassword?origurl=/System/ResetPassword%3fusername%3d%22%3Cscript%3Ealert(%273y3%200wn%20j00%20TWIKI%27)%3C/script%3E%3brefresh%3don
Spotted by
MichaelDaum. Brilliant.
Fixed by
KennethLavrsen
PS. yes this also applies to TWiki 4.2.4
i forwarded this report to
twiki-security@lists.sourceforge.net on 7 dec 2008