PacketFence - BTS - PacketFence
View Issue Details
0001292PacketFencesecuritypublic2011-10-03 11:032011-10-24 20:17
mattd 
obilodeau 
normalmajoralways
closedfixed 
devel 
3.0.23.0.2 
b3af2b197670c53ffb3992f3d14fbb028b35b927
0001292: XSS in web adminstration interface (login.php)
In the web administation login page (html/admin/login.php), the 'p' parameter, passed in as a HTTP GET parameter, is not properly escaped in the output. This leads to XSS.
A sample request, triggering the XSS:
login.php?p=%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E%3Cx%20x%3D%22
No tags attached.
patch security-fix-1292.patch (886) 2011-10-11 14:17
https://www.packetfence.org/bugs/file_download.php?file_id=107&type=bug
Issue History
2011-10-03 11:03mattdNew Issue
2011-10-03 11:05obilodeauStatusnew => assigned
2011-10-03 11:05obilodeauAssigned To => obilodeau
2011-10-03 11:06obilodeauNote Added: 0002310
2011-10-06 13:46obilodeauNote Added: 0002328
2011-10-07 22:06mattdNote Added: 0002331
2011-10-11 14:17obilodeaumtn revision => b3af2b197670c53ffb3992f3d14fbb028b35b927
2011-10-11 14:17obilodeauNote Added: 0002332
2011-10-11 14:17obilodeauStatusassigned => resolved
2011-10-11 14:17obilodeauFixed in Version => +1
2011-10-11 14:17obilodeauResolutionopen => fixed
2011-10-11 14:17obilodeauFile Added: security-fix-1292.patch
2011-10-17 10:37obilodeauNote Added: 0002362
2011-10-24 16:45obilodeauView Statusprivate => public
2011-10-24 20:15obilodeauTarget Version => 3.0.2
2011-10-24 20:15obilodeauNote Added: 0002386
2011-10-24 20:16obilodeauStatusresolved => closed
2011-10-24 20:17obilodeauFixed in Version+1 => 3.0.2

Notes
(0002310)
obilodeau   
2011-10-03 11:06   
Thanks for the report! We will fix this shortly.
(0002328)
obilodeau   
2011-10-06 13:46   
Ok, I'm looking at these now but first:

- Do you plan on getting CVE numbers for the vulnerabilities?
- Can you send me your full name and organization (optional) for the finding credits in the release notes.

Thanks,
(0002331)
mattd   
2011-10-07 22:06   
CVEs: Nope, I think it'd be better if you as vendor get them.
Credit: Matthew Daley.

Thanks!
(0002332)
obilodeau   
2011-10-11 14:17   
Fix committed in revno: b3af2b197670c53ffb3992f3d14fbb028b35b927
I requested CVE numbers.

Fix will be released in 3.0.2 shortly.

Those you can't wait or who won't upgrade in a timely fashion should apply the attached patch. It should apply cleanly on most packetfence versions known to man (it's long standing vuln).
(0002362)
obilodeau   
2011-10-17 10:37   
This vulnerability has been assigned: CVE-2011-4067
(0002386)
obilodeau   
2011-10-24 20:15   
fix released in 3.0.2