Notifications
Clear all

Security Vulnerability Found

3 Posts
3 Users
0 Reactions
1,926 Views
(@cattlyst)
Posts: 3
New Member
Topic starter
 

I found a security vulnerability which is consistent with all eFiction 2-3 releases.

You do not validate the form fields 'reviewer' or 'uid' when reviews are submitted. This can be used to post a review under someone elses logged in penname.
It is very easy to exploit this vulnerability, either by creating a dummy review page or by using one of the many freely available browser extensions which allow you to tamper with form data before it is sent.

Whilst this does not give anyone access to another person's account, it can certainly be used to pretend you are somone that you're not.

This can be fixed fairly easily with a few new lines of code around line 122 on ./reviews.php

Contact me if more information is needed.


 
Posted : 07/08/2007 1:02 am
(@tammy)
Posts: 2577
Member Moderator
 

Bump.  Should be fixed in 3.3.1.


 
Posted : 15/10/2007 5:35 pm
Jan_AQ
(@jan_aq)
Posts: 1300
Noble Member
 

Moving to solved.


Whoever said nothing is impossible never tried slamming a revolving door.

url: https://www.potionsandsnitches.org/fanfiction
php: 7.4.33 msql: 5.6.51-community GPL
efic version: 3.5.5 latest patches: yes
bridges: none mods: challenges, tracker, story end, beta, word

 
Posted : 25/01/2008 3:14 pm
Share: