Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0012033
TypeCategorySeverityReproducibilityDate SubmittedLast Update
design defect[Openbravo ERP] C. Securitymajoralways2010-01-21 17:592022-02-01 08:08
ReporterefrieseView Statuspublic 
Assigned ToTriage Platform Base 
PriorityhighResolutionopenFixed in Version
StatusacknowledgedFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSLinux 32 bitDatabasePostgreSQLJava version1.6.0_16
OS VersionCommunity ApplianceDatabase version8.3.8Ant version1.7.1
Product VersionSCM revision 
Review Assigned To
Web browser
ModulesCore
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0012033: Cross-site Scripting in BusinessPartner.html

DescriptionThe value of inpAD_Org_ID is not validated/escaped to prevent malicious code from being executed in the browser.
Steps To ReproduceThe TamperData plugin for Firefox or another proxy will be needed to reproduce. Visit /openbravo/info/BusinessPartner.html while using TamperData to set inpAD_Org_ID to:

inpAD_Org_ID=>%22%27><img%20src%3d%22javascript:alert('XSS')%22>

An alert box will display XSS.
Proposed SolutionThe value for inpAD_Org_ID should be escaped so that code will not be executed by the browser. More information can be found at http://www.owasp.org/index.php/Cross-site_Scripting_%28XSS%29 [^]
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]
blocks design defect 0019842 acknowledgedTriage Platform Base Review Cross-site Scripting 

-  Notes
(0052511)
AugustoMauch (administrator)
2012-09-24 23:39

Effort: 1
Impact: low
Plan: short

- Issue History
Date Modified Username Field Change
2010-01-21 17:59 efriese New Issue
2010-01-21 17:59 efriese Assigned To => alostale
2010-01-25 08:15 alostale Status new => scheduled
2010-01-25 08:15 alostale Assigned To alostale => shuehner
2012-02-20 11:21 shuehner Assigned To shuehner => alostale
2012-02-22 15:52 alostale Relationship added blocks 0019842
2012-02-22 15:53 alostale Type defect => design defect
2012-09-24 23:39 AugustoMauch Note Added: 0052511
2012-09-24 23:39 AugustoMauch Priority normal => high
2017-03-31 14:36 alostale Status scheduled => acknowledged
2017-04-10 14:35 alostale Assigned To alostale => platform
2022-02-01 08:08 alostale Assigned To platform => Triage Platform Base


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker