Sicherheitslücke - Liferay Portal Enterprise Edition
Tim Schughart <[email protected]> Sat, 3 Oct 2015 20:24:15 +0200
| Newsgroups | gmane.comp.security.fulldisclosure,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <[email protected]> |
--===============5703364540501609126==
Content-Type: multipart/signed;
boundary="Apple-Mail=_8D3E6D69-3145-4E9D-BD43-94CA8ED8B379";
protocol="application/pgp-signature"; micalg=pgp-sha512
--Apple-Mail=_8D3E6D69-3145-4E9D-BD43-94CA8ED8B379
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
charset=utf-8
Hey guys,
during a penatrationtest I have found an unknown persistent xss in =
liferay portal backend.
##################
#General Information#
##################
Manufacture description:
Liferay Portal is an enterprise-web-platform for the development of =
business solutions, which provides quick results and long-term values.
########
#Details#
########
=C2=B7 Product: Liferay =
Portal Enterprise Edition (6.2 EE SP13)
=C2=B7 Affected versions : All <=3D 6.2 EE =
SP13
=C2=B7 Type of attack: Persistent =
Cross Site Scripting
=C2=B7 Proof Of Concept: Yes, 6.2 =
EE SP13
=C2=B7 Authentication required: Yes
=C2=B7 Reason: Missing input =
validation
=C2=B7 Impact: =
Injection of malicious JavaScript code
######
#PoC#
######
You have to be authenticated in the administrator backend.
Here you have to browse to the control center:
- In configuration click on portal settings
- Select authentication
- Select ldap
- select add server
- input following code in server name
Value for ldap server name field:
Name_of_ldap_server<script>alert("XSS")</script>
The script is inserted to the configuration page persistent until the =
ldap server is deleted from database again.
Best regards / Mit freundlichen Gr=C3=BC=C3=9Fen
Tim Schughart
CEO | IT Security specialist
ProSec Networks
Website: http://www.prosec-networks.com =
<http://www.prosec-networks.com/>
E-Mail: [email protected] <mailto:[email protected]>
Phone: +49(0) 2621 9469 252
"This E-Mail communication may contain CONFIDENTIAL, PRIVILEGED and/or =
LEGALLY PROTECTED information and is intended only for the named =
recipient(s). Any unauthorized use, dissemination, copying or forwarding =
is strictly prohibited. If you are not the intended recipient and have =
received this email communication in error, please notify the sender =
immediately, delete it and destroy all copies of this E-Mail. VAT ID: =
DE290654714 legal domicile Koblenz.=E2=80=9C
"Diese E-Mail Mitteilung kann VERTRAULICHE, dem BERUFSGEHEIMNIS =
UNTERLIEGENDE und/oder RECHTLICH GESCH=C3=9CTZTE Informationen enthalten =
und ist ausschlie=C3=9Flich f=C3=BCr den/die genannten Adressaten =
bestimmt. Jede unbefugte Nutzung, Weitergabe, Vervielf=C3=A4ltigung oder =
Versendung ist strengstens verboten. Sollten Sie nicht der angegebene =
Adressat sein und diese E-Mail Mitteilung irrt=C3=BCmlich erhalten =
haben, informieren Sie bitte sofort den Absender, l=C3=B6schen diese =
E-Mail und vernichten alle Kopien. USt-IdNr.: DE290654714, Amtsgericht =
Koblenz."
--Apple-Mail=_8D3E6D69-3145-4E9D-BD43-94CA8ED8B379
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
filename=signature.asc
Content-Type: application/pgp-signature;
name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org
iQEcBAEBCgAGBQJWEB1PAAoJEBLxiVBPe43E93AH/1iRqDjEkVAt2OZMOLBjc3z/
b+ASYbtnj02i9RZ36uzNH5UE+WofmpMl7bMwpNhaEA/TdgO/gVyrvA29LP3Me42h
6hg84BjrJnWI0EbNCqVi8jQDTDemfYo8cSGVbqzuSRkvLfHg0baR1l4f5LChxvCz
P9LjrxIbxuujbqIl12e5t1a+YhfLafhBZ1WlwUvHyO2iPClX4U6Hsh8fMEnJZiFo
g2nNK7DBRO4Z++vxsPMI+Bs/oijF7Vk8rl1yB0fjL9IFJYY/ukK3Kgb//BeN/gP7
vY8JmcK9MMLdbyFVvakfTAfH6SR6CGAqILZCNoYabeitG+bozWtZDFAhc8TLd+g=
=1isp
-----END PGP SIGNATURE-----
--Apple-Mail=_8D3E6D69-3145-4E9D-BD43-94CA8ED8B379--
--===============5703364540501609126==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline