-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[SECURITY] Fix several cross-site scripting flaws #1
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -1109,6 +1109,9 @@ protected function init() | |
|
||
$this->gp = $this->utilityFuncs->getMergedGP(); | ||
|
||
if (!$this->settings['uniqueFormID']) { | ||
$this->gp['randomID'] = preg_replace('/[^0-9a-z]/', '', preg_quote($this->gp['randomID'])); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I know it is deprecated, obsolete and unmaintained but would a backport fix of v.2.4.1 to the Formhandler v2.0.2 (last one available for T3 6.2ELTS) be to "preg_replace / quote" and "htmlspecialchars" the same lines in the corresponding files in the older version? formhandler_2.0.2\Classes\Controller\Tx_Formhandler_Controller_Form.php There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Formhandler 2.0.2 released to TER should have them inside, or take a look by AoE https://github.com/AOEpeople/formhandler There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Yeah that's 2.0.2 but the old version with no fixes (like htmlspecialchars($name)) inside. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Then check the forks ( https://github.com/KaffDaddy/formhandler ) There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Thanks opi99 for that one. That's at least exactly what I have done: So it seems that is best one can do on a 6.2ELTS release. Also thanks tyll for discovering it 1year ago. |
||
} | ||
$randomID = $this->gp['randomID']; | ||
if (!$randomID) { | ||
if ($this->settings['uniqueFormID']) { | ||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -439,39 +439,39 @@ protected function fillDefaultMarkers() | |
} | ||
$markers['###HIDDEN_FIELDS###'] = ' | ||
<input type="hidden" name="id" value="' . $GLOBALS['TSFE']->id . '" /> | ||
<input type="hidden" name="' . $name . '" value="1" /> | ||
<input type="hidden" name="' . htmlspecialchars($name) . '" value="1" /> | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Why hsc this? FormValuesPrefix is a formhandler setting and isn't influenced by post/get vars? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Maybe @reinhardfuehricht can explain this. In some other places |
||
'; | ||
|
||
$name = 'randomID'; | ||
if ($this->globals->getFormValuesPrefix()) { | ||
$name = $this->globals->getFormValuesPrefix() . '[randomID]'; | ||
} | ||
$markers['###HIDDEN_FIELDS###'] .= ' | ||
<input type="hidden" name="' . $name . '" value="' . htmlspecialchars($this->gp['randomID']) . '" /> | ||
<input type="hidden" name="' . htmlspecialchars($name) . '" value="' . htmlspecialchars($this->gp['randomID']) . '" /> | ||
'; | ||
|
||
$name = 'removeFile'; | ||
if ($this->globals->getFormValuesPrefix()) { | ||
$name = $this->globals->getFormValuesPrefix() . '[removeFile]'; | ||
} | ||
$markers['###HIDDEN_FIELDS###'] .= ' | ||
<input type="hidden" id="removeFile-' . htmlspecialchars($this->gp['randomID']) . '" name="' . $name . '" value="" /> | ||
<input type="hidden" id="removeFile-' . htmlspecialchars($this->gp['randomID']) . '" name="' . htmlspecialchars($name) . '" value="" /> | ||
'; | ||
|
||
$name = 'removeFileField'; | ||
if ($this->globals->getFormValuesPrefix()) { | ||
$name = $this->globals->getFormValuesPrefix() . '[removeFileField]'; | ||
} | ||
$markers['###HIDDEN_FIELDS###'] .= ' | ||
<input type="hidden" id="removeFileField-' . htmlspecialchars($this->gp['randomID']) . '" name="' . $name . '" value="" /> | ||
<input type="hidden" id="removeFileField-' . htmlspecialchars($this->gp['randomID']) . '" name="' . htmlspecialchars($name) . '" value="" /> | ||
'; | ||
|
||
$name = 'submitField'; | ||
if ($this->globals->getFormValuesPrefix()) { | ||
$name = $this->globals->getFormValuesPrefix() . '[submitField]'; | ||
} | ||
$markers['###HIDDEN_FIELDS###'] .= ' | ||
<input type="hidden" id="submitField-' . htmlspecialchars($this->gp['randomID']) . '" name="' . $name . '" value="" /> | ||
<input type="hidden" id="submitField-' . htmlspecialchars($this->gp['randomID']) . '" name="' . htmlspecialchars($name) . '" value="" /> | ||
'; | ||
|
||
$name = 'formToken'; | ||
|
@@ -517,7 +517,7 @@ protected function fillDefaultMarkers() | |
$markers['###formValuesPrefix###'] = $this->globals->getFormValuesPrefix(); | ||
|
||
if ($this->gp['generated_authCode']) { | ||
$markers['###auth_code###'] = $this->gp['generated_authCode']; | ||
$markers['###auth_code###'] = htmlspecialchars($this->gp['generated_authCode']); | ||
} | ||
|
||
$markers['###ip###'] = \TYPO3\CMS\Core\Utility\GeneralUtility::getIndpEnv('REMOTE_ADDR'); | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If I understand this correctly, if 'uniqueFormID' is set, we have the same issue.
So removing this if statement?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Maybe move the
preg_replace
to line 1120 and sanitize$randomID
unconditionally.