6.0.0-git
2021-01-18

[#12803] CSRF and XSS in in Save search as a virtual address book
Summary CSRF and XSS in in Save search as a virtual address book
Queue Turba
Queue Version 4.1.2
Type Bug
State Resolved
Priority 3. High
Owners jan (at) horde (dot) org
Requester m.benetrix (at) e-secure (dot) com (dot) au
Created 2013-10-28 (2639 days ago)
Due 11/02/2013 (2634 days ago)
Updated 2013-10-29 (2638 days ago)
Assigned
Resolved 2013-10-29 (2638 days ago)
Milestone
Patch No

History
2013-10-29 11:19:31 Jan Schneider Assigned to Jan Schneider
State ⇒ Resolved
 
2013-10-29 11:19:22 Git Commit Comment #2 Reply to this comment
Changes have been made in Git (master):

commit 74f9add4ad86c29b608270e33b17426163b3c8cf
Author: Jan Schneider <jan@horde.org>
Date:   Tue Oct 29 12:19:06 2013 +0100

     Token-protect vbook form (Bug #12803).

  turba/search.php                      |   67 
+++++++++++++++++++--------------
  turba/templates/search/vbook.html.php |    1 +
  2 files changed, 40 insertions(+), 28 deletions(-)

http://git.horde.org/horde-git/-/commit/74f9add4ad86c29b608270e33b17426163b3c8cf
2013-10-28 22:03:50 Michael Slusarz Version ⇒ 4.1.2
Queue ⇒ Turba
Priority ⇒ 3. High
 
2013-10-28 21:37:04 m (dot) benetrix (at) e-secure (dot) com (dot) au Comment #1
Type ⇒ Bug
State ⇒ Unconfirmed
Priority ⇒ 2. Medium
Summary ⇒ CSRF and XSS in in Save search as a virtual address book
Due ⇒ 2013-11-02
Queue ⇒ Horde Groupware Webmail Edition
Milestone ⇒
Patch ⇒ No
Reply to this comment
CSRF and XSS were found in the "Save Search as a virtual address book" 
functionality.  A malicious attacker could launch a CSRF attack and 
makes the user to save a malicious code into the "save search".This 
functionality was found to miss the user's input sanitisation, making 
it vulnerable to XSS.

So in order to exploit the XSS, a CSRF has to be launched before.

Saved Queries