Last modified: 2014-11-14 19:59:52 UTC
There's an XSS issue on Semantic MediaWiki's Special:CreateForm page in the 'form_name' parameter. Example XSS value: ""><script>alert("3")</script> Video example: http://youtu.be/c1QkVOUEjMQ Screenshot: http://i1256.photobucket.com/albums/ii488/testfortest/123/ww.png?t=1338819700 This issue was reported to Mozilla by Sony <insecurity.ro@gmail.com>. Mozilla is tracking this as https://bugzilla.mozilla.org/show_bug.cgi?id=761114.
Created attachment 10820 [details] Use Html::input instead of writing string directly. Confirmed in 2.4.2. Patch attached.
I checked in the change - thanks for the patch. Hopefully this was the last bit of hardcoded HTML in the Semantic Forms code...
Where can I get an updated copy of Semantic Forms that includes this fix?
It's available already via Git - there's not yet a new downloadable version with the fix. That will hopefully come out soon-ish.
Yaron, I pull it from svn just now (following the link on http://www.mediawiki.org/wiki/Extension:Semantic_Forms/Download_and_installation), and svn does *not* have the fix yet. Which git repo is it in?
(In reply to comment #5) > Yaron, I pull it from svn just now (following the link on > http://www.mediawiki.org/wiki/Extension:Semantic_Forms/Download_and_installation), > and svn does *not* have the fix yet. Which git repo is it in? I found it: https://gerrit.wikimedia.org/r/gitweb?p=mediawiki/extensions/SemanticForms.git;a=tree Specific commits: https://gerrit.wikimedia.org/r/gitweb?p=mediawiki/extensions/SemanticForms.git;a=commit;h=5935a8ff15e019844913c11e2ac8ddac660e2d8e https://gerrit.wikimedia.org/r/gitweb?p=mediawiki/extensions/SemanticForms.git;a=commit;h=f7f0c5794b9632477edba22bd2c11682f697a2a1
Oh, yeah - all the documentation still needs to be change from SVN to Git.
Thanks for updating the git link. It looks like the zip files have not been updated: http://discoursedb.org/SemanticForms/semantic_forms_2.4.2.tar.gz http://discoursedb.org/SemanticForms/semantic_forms_2.4.2.zip And the google project for the bundle also has the old version of the files: https://code.google.com/p/semantic-mediawiki-bundle/ Yaron, can you handle those as well?
No, indeed, those haven't been updated yet - that will happen when there's a new version of Semantic Forms and Semantic Bundle, respectively.
When is a new version expected to be released?
Hi - it was released yesterday. :)
(In reply to comment #11) > Hi - it was released yesterday. :) Awesome, do you know how long it should take for https://code.google.com/p/semantic-mediawiki-bundle/downloads/list to be updated? Cheers
That one could be a while, unfortunately - maybe a month or two.