help to better help you:

Please: add always Joomla / JEM version and details to your posts, so we can try to reproduce your issue!

[SOLVED] Possible XSS issue

[SOLVED] Possible XSS issue

6 months 1 week ago - 6 months 1 week ago
#32761
Hi, we received this information about an XSS vulnerability on our page: openbugbounty > reports > 4143654
We think we traced it back to the JEM event search. We also received further details in an email we don't want to post publicly. It contains an example URL that injects code which is indeed executed in the browser. We will happily forward the email to you if you give us an address that verifiably belongs to the JEM team.

Joomla version: 5.3.2
JEM version: 4.3.3

Are you aware of this? Is this an issue?

Thanks for your great work,
Falk for Jungenarbeit
Last edit: 6 months 1 week ago by larskaufbach.

Please Log in or Create an account to join the conversation.

Re: [SOLVED] Possible XSS issue

6 months 1 week ago
#32763
Hello there,

We did recieve your email yesterday with the relevant example URL. It's shared between the team on a non-public part of this forum.

Thanks for reporting this!

Please Log in or Create an account to join the conversation.

Re: [SOLVED] Possible XSS issue

6 months 1 week ago
#32764
Nice, thanks.

Please Log in or Create an account to join the conversation.

Re: [SOLVED] Possible XSS issue

6 months 3 days ago
#32776
Just a quick note:
We responded yesterday via email.
The following user(s) said Thank You: jojo12

Please Log in or Create an account to join the conversation.

Re: [SOLVED] Possible XSS issue

6 months 1 day ago
#32782
Thanks for getting back via email! The info is sent to the developers just now.

Please Log in or Create an account to join the conversation.

Re: [SOLVED] Possible XSS issue

5 months 3 weeks ago
#32811
Sanitize user input to prevent reflected XSS in the search field
Proper escaping has been added to the filter_search input using htmlspecialchars() to prevent XSS via injected attributes.
User input is now safely rendered inside the value attribute.

See the commit: github.com/jemproject/JEM-Project/commit/9a618582db35f6a46c2c8b17d223f5b043125061

This fix will be included in the upcoming JEM 4.3.4 release.
The following user(s) said Thank You: hekla

Please Log in or Create an account to join the conversation.

Time to create page: 0.569 seconds