Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • fusiondirectory fusiondirectory
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 33
    • Issues 33
    • List
    • Boards
    • Service Desk
    • Milestones
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Terraform modules
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • fusiondirectoryfusiondirectory
  • fusiondirectoryfusiondirectory
  • Issues
  • #6137
Closed
Open
Issue created Apr 28, 2020 by bmortier@bmortierMaintainer

XSS in management filters

I found a cross site scripting issue in FusionDirectory. You can easily reproduce the issue with the following procedures:

  1. Launch FusionDirectory 1.2.1

$ git clone https://github.com/hrektts/docker-fusiondirectory.git $ docker-compose up -d

  1. Open http://localhost:10080/fd/ with the Browser
  2. Enter fd-admin / fdadminpwd to sign in
  3. Go to "users" in the left menu
  4. Input "et7s7'onfocus='alert(1)'autofocus='laqnc" to a textfield in Filter on the right side

This issue might remain in the latest version. For fixing this issue, the user input must be escaped properly.

Regards, Takumi

Edited Apr 28, 2020 by bmortier
Assignee
Assign to
Time tracking