logviewer icon indicating copy to clipboard operation
logviewer copied to clipboard

The LogViewer component is vulnerable to Cross Site Scripting.

Open cjke opened this issue 10 years ago • 5 comments

We've had our soon to be launched site externally security tested. The security auditors use the AS/NZS 31000:2009 standard for assessing risk. A few issues recorded were linked directly to the LogViewer component. I will include a new issue per issue recorded by security audit.

Consequence High This flaw can be exploited to affect the integrity of all applications served from the same server.

The LogViewer component parses the Apache log files and presents the entries to the user. If a log entry contains any HTML component, including Javascript, it is sent to the browser without validation. This introduces a cross site scripting vulnerability.

capture

capture2

cjke avatar Jun 15 '14 22:06 cjke

I'm having some issues with my dev enviornment at the moment, but I've found a fix for this issue and #67. I will get them fixed as soon as I can.

mikemand avatar Jun 22 '14 16:06 mikemand

What is the status of this?

opheliadesign avatar Oct 06 '14 18:10 opheliadesign

any news ?

natali9t9 avatar Nov 13 '14 10:11 natali9t9

Was this ever fixed? If not, I will create a pull request to fix the issues

cjke avatar Feb 18 '15 03:02 cjke

I have not had any time lately to fix this bug and #67. If @cjke would like to open a pull request that fixes it, I will review and (most likely) accept.

mikemand avatar Mar 02 '15 23:03 mikemand