•  
      request #3261 XSS vulnerability in Docman
    Infos
    #3261
    Mohamed Amin Doghri (doghrim)
    2013-05-07 18:24
    2013-05-02 17:38
    2081
    Details
    XSS vulnerability in Docman
    Js code is interpreted by navigator when put in URL.

    To reproduce :

    Login in tuleap

    Go to : https://tuleap.net/plugins/docman/?group_id=101&action=show&id=421&report=Tree"onmouseover="alert(255)"

    You will get an alert(255) if you overfly document links

    Doc/Documentation manager
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Denis PILAT (denis_pilat), Ahmed HOSNI (hosniah)
    Stage
    Mohamed Amin Doghri (doghrim)
    Closed
    2013-05-07
    Attachments
    Empty
    References
    References list is empty

    Follow-ups

    User avatar
    Available in Tuleap 6.0.99.1

    • Status changed from Under implementation to Closed
    • Close date set to 2013-05-07
    • Is an Enhancement or an internal improvement? set to
    User avatar
    Hello,

    I reproduce the bug. We will have a look on it quickly !

    • Category set to Doc/Documentation manager
    • Status changed from New to Verified
    • Platform set to