| Priority: | CurrentState: | AppliesTo: | Component: | WaitingFor: |
|---|---|---|---|---|
| Urgent | Closed | Engine | KennethLavrsen |
http://somedomain.com/foswiki/bin/login/System/ResetPassword?origurl=/System/ResetPassword%3fusername%3d%22%3Cscript%3Ealert(%273y3%200wn%20j00%20TWIKI%27)%3C/script%3E%3brefresh%3donSpotted by MichaelDaum. Brilliant. Fixed by KennethLavrsen PS. yes this also applies to TWiki 4.2.4
| Summary | ORIGURL used in template login used for example for reset password is an XSS attach vector |
| ReportedBy | Foswiki:Main.KennethLavrsen |
| Codebase | trunk |
| SVN Range | TWiki-4.2.3, Wed, 06 Aug 2008, build 17396 |
| AppliesTo | Engine |
| Component | |
| Priority | Urgent |
| CurrentState | Closed |
| WaitingFor | KennethLavrsen |
| Checkins | |
| TargetRelease | patch |
| ReleasedIn | 1.0.0 |
