Security:Security Advisories/BSSA-2022-01 and Announcement/XSS attack: Difference between pages

(Difference between pages)
m (Reverted edits by Margit.link-rodrigue (talk) to last revision by Mglaser)
Tag: Rollback
 
No edit summary
Tag: 2017 source edit
 
Line 1: Line 1:
{| class="wikitable"
{{Featurepage|featured=true|featuredesc=Patch Release 4.1.3 contains an important '''security fix''' for a “reflected XSS” attack. <span class="bi bi-exclamation-circle-fill" style="color:orange"></span>|featurestart=04/25/2022}}
|+
==Event==
!
XSS attack vector in ''mwstake/mediawiki-component-commonuserinterface.'' 
!
|-
|Date
|2022-01-31
|-
|Severity
|Medium
|-
|Affected
|BlueSpice 3.x, BlueSpice 4.x
|-
|Fixed in
|BlueSpice 3.2.9, BlueSpice 4.1.1
|}


== Problem ==
== Evaluation of the vulnerability in BlueSpice ==
Users are able to inject arbitrary HTML (XSS) on Special:SearchCenter, using the search term. This can be triggered via URL.
The value from 'title' parameter get's unsanitized to the output (e.g. in 'list-group-item').


== Solution ==
[[Setup:Release Notes#4.1.3|Patch release 4.1.3]] contains an important security-fix for this attack.
Upgrade to BlueSpice 4.1.1


== Acknowledgements ==
The [[Security:Security_Advisories/BSSA-2022-02|corresponding CVE entry]] is still pending and will be published soon. It is highly recommended that all users update their installation of BlueSpice 4 as soon as possible.
Special thanks to the security team of an undisclosed customer
 
[[de:Meldung/XSS attack]]
[[en:{{FULLPAGENAME}}]]

Revision as of 09:16, 26 April 2022

Event

XSS attack vector in mwstake/mediawiki-component-commonuserinterface.

Evaluation of the vulnerability in BlueSpice

The value from 'title' parameter get's unsanitized to the output (e.g. in 'list-group-item').

Patch release 4.1.3 contains an important security-fix for this attack.

The corresponding CVE entry is still pending and will be published soon. It is highly recommended that all users update their installation of BlueSpice 4 as soon as possible.

No categories assignedEdit

Discussions