•  
      request #30734 XSS through the name of a color of select box values
    Infos
    #30734
    Nicolas Terray (nterray)
    2023-03-06 09:03
    2023-02-01 15:23
    32325
    Details
    XSS through the name of a color of select box values

    XSS can injected in the name of a color of select box values of a tracker and then reflected in the tracker administration. A previous request #11685 removed injection points in trackers and agile dashboard, but new injection point has been introduced lately.

    Impact

    An attacker could use this vulnerability to force a victim to execute uncontrolled code.
    CVSSv3 score: 5.5 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N)

    Exploitation

    As a tracker admin edit the color of a selectbox value and intercept the request to replace the name of the color by a payload like "><script>alert(1)</script> to demonstrate the issue.

    References

    CWE 79
    OWASP Cross-site Scripting
    CVE-2023-23938

    Trackers
    14.5
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Nicolas Terray (nterray)
    Closed
    2023-02-01
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2023-02-02 10:12

    CVE-2023-23938 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2023-02-01 16:31

    Integrated into Tuleap 14.5.99.4.


    • Status changed from Under review to Closed
    • Connected artifacts
    • Close date changed from 2018-06-25 to 2023-02-01
    User avatar
    Thomas Gerbet (tgerbet)2023-02-01 15:34
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes