Closed Bug 961656 Opened 11 years ago Closed 11 years ago

XSS in report.cgi with real name of user

Categories

(Bugzilla :: Reporting/Charting, defect)

x86_64
Linux
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 924932

People

(Reporter: hofusec, Unassigned)

Details

I have found a XSS vulnerability in Bugzilla 4.4: Steps to reproduce: - set the real name of a bugzilla user to " onmouseover=alert(1) style=" (including the ") - go to “/query.cgi?format=report-table” set Multiple Tables = 'Reporter real name' set Detailed Bug Information → Bugs numbered, to a bug number submitted from the user and submit the formular - move the mouse over the generated html table, an alert box will appear
Sorry, already fixed in 4.4.1.
OK. So can we resolve this bug? Gerv
Assignee: general → charting
Group: bugzilla-security
Status: UNCONFIRMED → RESOLVED
Closed: 11 years ago
Component: Bugzilla-General → Reporting/Charting
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.