Persistent xss liferay enterprise cms

Tim Schughart <[email protected]> Wed, 07 Oct 2015 07:58:50 +0200
Newsgroups gmane.comp.security.web-applications
Message-ID <[email protected]>
Hey guys,

during a penatrationtest I have found an unknown persistent xss in liferay p=
ortal backend. Liferay is already informed.=20

##################
#General Information#
##################


Manufacture description:
Liferay Portal is an enterprise-web-platform for the development of business=
 solutions, which provides quick results and long-term values.


########
#Details#
########
=C2=B7         Product:                    Liferay Portal Enterprise Edition=
 (6.2 EE SP13)
=C2=B7         Affected versions :            All <=3D 6.2 EE SP13
=C2=B7         Type of attack:                Persistent  Cross Site Scripti=
ng
=C2=B7         Proof Of Concept:                Yes, 6.2 EE SP13
=C2=B7         Authentication required:        Yes
=C2=B7         Reason:                    Missing input validation
=C2=B7         Impact:                        Injection of malicious  JavaSc=
ript code

######
#PoC#
######
You have to be authenticated in the administrator backend.
Here you have to browse to the control center:
- In configuration click on portal settings
- Select authentication
- Select ldap
- select add server
- input following code in server name

Value for ldap server name field:
Name_of_ldap_server<script>alert("XSS")</script>

The script is inserted to the configuration page persistent until the ldap s=
erver is deleted from database again.

#Protection
Set XSS Header and create Waf rule until its patched.=20

Best regards / Mit freundlichen Gr=C3=BC=C3=9Fen

Tim Schughart




This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------