Persistent xss liferay enterprise cms
Tim Schughart <[email protected]> Wed, 07 Oct 2015 07:58:50 +0200
| Newsgroups | gmane.comp.security.web-applications |
|---|---|
| Message-ID | <[email protected]> |
Hey guys,
during a penatrationtest I have found an unknown persistent xss in liferay p=
ortal backend. Liferay is already informed.=20
##################
#General Information#
##################
Manufacture description:
Liferay Portal is an enterprise-web-platform for the development of business=
solutions, which provides quick results and long-term values.
########
#Details#
########
=C2=B7 Product: Liferay Portal Enterprise Edition=
(6.2 EE SP13)
=C2=B7 Affected versions : All <=3D 6.2 EE SP13
=C2=B7 Type of attack: Persistent Cross Site Scripti=
ng
=C2=B7 Proof Of Concept: Yes, 6.2 EE SP13
=C2=B7 Authentication required: Yes
=C2=B7 Reason: Missing input validation
=C2=B7 Impact: Injection of malicious JavaSc=
ript code
######
#PoC#
######
You have to be authenticated in the administrator backend.
Here you have to browse to the control center:
- In configuration click on portal settings
- Select authentication
- Select ldap
- select add server
- input following code in server name
Value for ldap server name field:
Name_of_ldap_server<script>alert("XSS")</script>
The script is inserted to the configuration page persistent until the ldap s=
erver is deleted from database again.
#Protection
Set XSS Header and create Waf rule until its patched.=20
Best regards / Mit freundlichen Gr=C3=BC=C3=9Fen
Tim Schughart
This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now!
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------