Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0014857Openbravo ERPC. Securitypublic2010-10-12 01:152022-02-01 08:08
cmlh_id_au 
Triage Platform Base 
highmajoralways
acknowledgedopen 
20Community Appliance
 
 
Core
No
0014857: Cross Site Scripting (XSS) - Reflected - ReportInvoiceCustomerFilterJR.html - "inpProjectkind" Parameter
The value of the "inpProjectkind" Parameter is not validated and/or escaped during the HTTP GET Request of /openbravo/ad_reports/ReportInvoiceCustomerFilterJR.html and hence is vulnerable to Reflected Cross Site Scripting (XSS)
1. Copy and paste the following URL into Firefox after authenticating to http://demo2.openbravo.com: [^]
http://demo2.openbravo.com/openbravo/ad_reports/ReportInvoiceCustomerFilterJR.html?Command=&inpProjectpublic=PR&inpCurrencyId=238&inpProjectkind=RO%3Cimg%20src%3da%20onerror%3dalert%28%27XSS%27%29%3E&inpSalesRepId=&inpDateFrom=555-555-0199@example.com&inpProjectphase=PR&inpDateTo=555-555-0199@example.com&inpcRegionId=114&inpcProjectId=&inpcProjectId_D=555-555-0199@example.com&inpcBPartnerId=&inpProjectstatus=OR [^]

2. A Javascript Alert Box will display "XSS" as per the attached screenshot.
Validate and escape the value of the "inpProjectkind" Parameter on the server side i.e. prior to the Javascript being executed by the web browser.
No tags attached.
blocks design defect 0019842 acknowledged Triage Platform Base Review Cross-site Scripting 
jpg Cross_Site_Scripting_(XSS)_-_Reflected_-_ReportInvoiceCustomerFilterJR.html_-_inpProjectkind_Parameter.jpg (83,829) 2010-10-12 01:15
https://issues.openbravo.com/file_download.php?file_id=3215&type=bug
jpg
Issue History
2010-10-12 01:15cmlh_id_auNew Issue
2010-10-12 01:15cmlh_id_auAssigned To => alostale
2010-10-12 01:15cmlh_id_auFile Added: Cross_Site_Scripting_(XSS)_-_Reflected_-_ReportInvoiceCustomerFilterJR.html_-_inpProjectkind_Parameter.jpg
2010-10-12 01:16cmlh_id_auIssue Monitored: cmlh_id_au
2010-10-12 01:20cmlh_id_auNote Added: 0031770
2010-10-12 01:21cmlh_id_auNote Deleted: 0031770
2010-10-25 08:56alostaleAssigned Toalostale => shuehner
2010-10-25 08:56alostaleStatusnew => scheduled
2012-02-20 11:20shuehnerAssigned Toshuehner => alostale
2012-02-22 15:52alostaleRelationship addedblocks 0019842
2012-02-22 15:54alostaleTypedefect => design defect
2012-09-24 23:25AugustoMauchNote Added: 0052467
2012-09-24 23:25AugustoMauchPrioritynormal => high
2017-03-31 14:36alostaleStatusscheduled => acknowledged
2017-04-10 14:34alostaleAssigned Toalostale => platform
2022-02-01 08:08alostaleAssigned Toplatform => Triage Platform Base

Notes
(0052467)
AugustoMauch   
2012-09-24 23:25   
Effort: 1
Impact: low
Plan: short