Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2.2.7 Cross Site Scripting Vulnerability #17

Closed
fgeek opened this issue Mar 5, 2015 · 5 comments
Closed

2.2.7 Cross Site Scripting Vulnerability #17

fgeek opened this issue Mar 5, 2015 · 5 comments

Comments

@fgeek
Copy link

fgeek commented Mar 5, 2015

http://seclists.org/bugtraq/2015/Mar/15

@halamix2
Copy link
Contributor

halamix2 commented Jun 17, 2017

I'll publish Search.php fix shortly but I were unable to reproduce POST XSS in profile.php
( I'm not sure if it wasn't fixed in this commit ).
Edit: I see it now

@fgeek
Copy link
Author

fgeek commented Jul 1, 2017

CVE-2015-2217 has been assigned for this issue. Please use it in your ChangeLog when releasing new version, thanks. Could you create new release with this fix, thanks?

@phpcodex
Copy link
Contributor

phpcodex commented Jul 1, 2017

I'll have a look in to this issue, it would need confirming that it is fixed before we release the next version.

@phpcodex phpcodex reopened this Jul 1, 2017
@phpcodex phpcodex added the bug label Jul 1, 2017
@phpcodex phpcodex added this to Analysis in Development Jul 1, 2017
@halamix2 halamix2 added this to the 2.2.8 milestone Jul 1, 2017
@halamix2 halamix2 removed the 2.2.8 label Jul 1, 2017
@phpcodex
Copy link
Contributor

phpcodex commented Jul 1, 2017

So looking at this, it is not fixed, but we have to cURL it to do the final test as I can't replicate.

@phpcodex
Copy link
Contributor

phpcodex commented Jul 1, 2017

Okay, this is official, bug has been previously sanitized. Cannot reproduce. I can change all the detail's in cURL but unable to create the bug, even using the original CVE.

@phpcodex phpcodex closed this as completed Jul 1, 2017
@phpcodex phpcodex moved this from Analysis to Done in Development Jul 1, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Development

No branches or pull requests

3 participants