News

Aug 18, 2010
Category: General
Posted by: skypanther
Version 2.4 is in development, though proceeding more slowly than I had hoped. In addition to bug fixes and rolling in the XSS patch, this version will introduce a few new features.
Jul 25, 2010
Category: General
Posted by: skypanther
I've published a patch that should fix the XSS vulnerabilities previously identified. See my forum post for more information.

Page 1 of 10  > >>

 
2.3b



 

Jul 21, 2010

XSS vulnerabilities


We have been informed of some security issues that will be addressed in an upcoming patch or new release of FestOS. In a nutshell, some of the admin pages do not fully filter data which could permit a malicious user to force data into your database.
Category: General
Posted by: skypanther

The affected administration pages require the user to be logged on with sufficient permissions. A malicious user cannot simply load the form processing page and use it to insert data. They must be logged on as an admin or the page will halt.

Thus the real risk arises when FestOS administrators do not log out before visiting other web sites. In such a situation, code at those sites could capitalize on the lingering logged on state, craft a special request to your FestOS site, and modify data (update a web page, add an administrator, etc.).

Until a fix is published, you can easily eliminate this vulnerability by logging out before leaving the site. (also, don't visit another site in another browser tab or window while remaining logged onto the FestOS admin system)

  Next page: FestOS DIY Edition