Uploaded image for project: 'Hippo CMS'
  1. Hippo CMS
  2. CMS-2994

Prevent javascript and JCR SQL injection

    XMLWordPrintable

Details

    • Bug
    • Status: Closed
    • High
    • Resolution: Fixed
    • r2.06.07
    • Icebox
    • None
    • None

    Description

      In the CMS' editor it is possible to save a piece of javascript code. When another user loads that same document, it is possible to hijack that user's session. Unfortunately I don't have a clear use case, since the person who found out is not in the office atm.

      Another security vulnerability is JCR injection (which is similar to SQL injection), although the hacker needs enough security rights to effectively use it. Alas, I also don't have clear usecases. I will provide use cases later when I contact the security guy

      Attachments

        Activity

          People

            Unassigned Unassigned
            dennis dam Dennis Dam (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: