Summary: | CVE-2011-3352 zikula (v1.3.x): XSS flaw due improper sanitization of 'themename' parameter by setting default, modifying and deleting themes | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | david, vdanen |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2011-09-08 13:23:28 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: |
Description
Jan Lieskovsky
2011-09-08 13:13:58 UTC
Provided PoC (from [1], [2]): ============================= http://host/index.php?module=theme&type=admin&func=setasdefault&themename=%3Cscript%3Ealert%28docu ment.cookie%29%3C/script%3E CVE Request: [4] http://www.openwall.com/lists/oss-security/2011/09/08/5 This issue did NOT affect the versions of the zikula package, as shipped with Fedora release of 14 and 15 (these versions do not contain the affected code in question yet). -- This issue did NOT affect the versions of the zikula package, as present within EPEL-5 and EPEL-6 repositories (the zikula package versions there do not contain the vulnerable code in question yet). This issue was assigned the name CVE-2011-3352. A potentially duplicate CVE identifier of CVE-2011-3979 has been also assigned to this issue. Checking with Mitre: [5] http://www.openwall.com/lists/oss-security/2011/10/04/3 which CVE identifier is the proper one to be used to reference to this issue. Will update this bug later yet, if / once necessary. |