#1373 XSS attacks on the dogtag administration page (port 9180, port 9444)
Closed: Fixed None Opened 9 years ago by mharmsen.

It appears that the administation page of dogtag PKI is vulnerable to XSS
attacks, wether through the SSL administration page, or the non-SSL
administration page.

How reproducible:

Open these URLs :

Steps to Reproduce:

1. Browse similar URLs : https://ipa_server:9444/ca/ee/ca/profileSelect?profile
2. Have a javascript pop-up being display.

Actual results:

Non-Filtered HTML code that triggers javascript

Expected results:

Filtered HTML code

Ported changes from other release over, tested the listed test cases to work fine. Submitting patch for review.

Patch reviewed, pushed to master:

Metadata Update from @mharmsen:
- Issue assigned to jmagne
- Issue set to the milestone: 10.2.4

7 years ago

