View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 20390 | Bug reports | Security | public | 2025-12-18 18:45 | 2025-12-19 08:46 |
| Reporter | jarrod.c | Assigned To | tibor.pacalat | ||
| Priority | none | Severity | minor | ||
| Status | feedback | Resolution | open | ||
| Product Version | 6.6.x | ||||
| Summary | 20390: Phishing by Navigating Browser Tabs | ||||
| Description | VulnerabilitySurvey is affected by the following vulnerability: CWE-1022: Use of Web Link to Untrusted Target with window.opener Access Example
Remedy
| ||||
| Steps To Reproduce | Steps to reproduce(Replace this text with detailed step-by-step instructions on how to reproduce the issue) Expected result(Write here what you expected to happen) Actual result(Write here what happened instead) | ||||
| Tags | No tags attached. | ||||
| Bug heat | 254 | ||||
| Complete LimeSurvey version number (& build) | 6.16.2+251209 | ||||
| I will donate to the project if issue is resolved | No | ||||
| Browser | |||||
| Database type & version | Irrelevant | ||||
| Server OS (if known) | |||||
| Webserver software & version (if known) | |||||
| PHP Version | Irrelevant | ||||
|
While reviewing the source code, I found that the href target="_blank" attribute is used 102 times. |
|
|
Unsure www.limesurvey.org is an untrusted target? |
|
|
I didn't set as private since it's included in core and not a way to add such link by simple user of limesurvey instance. |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2025-12-18 18:45 | jarrod.c | New Issue | |
| 2025-12-18 19:19 | jarrod.c | Note Added: 84041 | |
| 2025-12-18 19:19 | jarrod.c | Bug heat | 250 => 252 |
| 2025-12-19 08:45 | DenisChenu | Note Added: 84042 | |
| 2025-12-19 08:45 | DenisChenu | Bug heat | 252 => 254 |
| 2025-12-19 08:45 | DenisChenu | Assigned To | => tibor.pacalat |
| 2025-12-19 08:45 | DenisChenu | Status | new => assigned |
| 2025-12-19 08:46 | DenisChenu | Status | assigned => feedback |
| 2025-12-19 08:46 | DenisChenu | Note Added: 84043 |