View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
06546 | Bug reports | Security | public | 2012-09-04 19:04 | 2012-09-09 15:34 |
Reporter | Assigned To | jcleeland | |||
Priority | normal | Severity | partial_block | ||
Status | closed | Resolution | fixed | ||
Product Version | 1.92+ | ||||
Fixed in Version | 1.92+ | ||||
Summary | 06546: SQL injection in userrighthandling.php - parameter "ugid" | ||||
Description | The "ugid" parameter doesn't get sanitized before beeing used to File: $LIMESURVEY/admin/userrighthandling.php | ||||
Steps To Reproduce | 1) Log in as admin | ||||
Additional Information | Discovered by Markus Piéton (it.sec GmbH & Co. KG) | ||||
Tags | No tags attached. | ||||
Attached Files | |||||
Bug heat | 256 | ||||
Complete LimeSurvey version number (& build) | 120822 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | |||||
Database type & version | MySQL | ||||
Server OS (if known) | Linux | ||||
Webserver software & version (if known) | Apache | ||||
PHP Version | PHP | ||||
Hi Jason, Maybe you can have a look and fix it or add a comment and assign it to Carsten if he should have a look later. |
|
Fix committed to master branch: http://bugs.limesurvey.org/plugin.php?page=Source/view&id=9451 |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2012-09-04 19:04 |
|
New Issue | |
2012-09-04 19:04 |
|
File Added: sql-injection-ugid.pdf | |
2012-09-06 15:22 | Mazi | Assigned To | => jcleeland |
2012-09-06 15:22 | Mazi | Status | new => assigned |
2012-09-06 15:22 | Mazi | Issue Monitored: c_schmitz | |
2012-09-06 15:23 | Mazi | Note Added: 20632 | |
2012-09-08 01:27 | jcleeland | Changeset attached | => LimeSurvey master cf84cb62 |
2012-09-08 01:27 | jcleeland | Note Added: 20643 | |
2012-09-08 01:27 | jcleeland | Resolution | open => fixed |
2012-09-08 01:28 | jcleeland | Status | assigned => resolved |
2012-09-08 01:28 | jcleeland | Fixed in Version | => 1.92+ |
2012-09-09 15:34 | c_schmitz | Status | resolved => closed |
2021-08-02 20:51 | guest | Bug heat | 254 => 256 |