Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Piwik XSS #1269

Closed
mattab opened this issue Apr 1, 2010 · 5 comments
Closed

Piwik XSS #1269

mattab opened this issue Apr 1, 2010 · 5 comments
Assignees
Labels
Bug For errors / faults / flaws / inconsistencies etc. Critical Indicates the severity of an issue is very critical and the issue has a very high priority.
Milestone

Comments

@mattab
Copy link
Member

mattab commented Apr 1, 2010

I saw on twitter a Piwik XSS tweet pointing to http://packetstormsecurity.org/1003-exploits/piwik-xss.txt

we should fix it and check other variables to ensure there is no xss left.

I re-enabled the sensitive ticket plugin for this one, and set it to sensitive, which seems to work.

@robocoder
Copy link
Contributor

(In [2038]) refs #1269

@robocoder
Copy link
Contributor

(In [2039]) refs #1269

@robocoder
Copy link
Contributor

(In [2047]) refs #1269

@robocoder
Copy link
Contributor

While [fixed the issue (by validating/filtering/escaping form_url), 2047 is a better solution -- it eliminates form_url entirely as a parameter/hidden form field.

I've drafted a blog entry for the security advisory and will request a CVE later for the 0.6 release.

@mattab
Copy link
Member Author

mattab commented Apr 24, 2010

I disabled the sensitivity plugin for now, also closing this.. please reopen if there is open issue.

@mattab mattab added this to the Piwik 0.6 milestone Jul 8, 2014
This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug For errors / faults / flaws / inconsistencies etc. Critical Indicates the severity of an issue is very critical and the issue has a very high priority.
Projects
None yet
Development

No branches or pull requests

2 participants