Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 401993 - www-apps/twiki "organization" field is not properly sanitized
Summary: www-apps/twiki "organization" field is not properly sanitized
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/47784/
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-02-02 21:34 UTC by Michael Harrison
Modified: 2012-03-03 20:17 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Harrison 2012-02-02 21:34:28 UTC
Input passed via the Organization field when registering or editing a user is not properly sanitized before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed.

The vulnerability is confirmed in version 5.1.1. Other versions may also be affected.

Original Advisory:
http://st2tea.blogspot.com/2012/01/cross-site-scripting-twiki.html
Comment 1 Markos Chandras (RETIRED) gentoo-dev 2012-03-03 18:48:23 UTC
package has been removed from tree
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2012-03-03 20:17:48 UTC
(In reply to comment #1)
> package has been removed from tree

Thanks. Closing noglsa since twiki was only ever ~arch.