Sony has discovered multiple vulnerabilities in Foswiki, which can be exploited by malicious users to conduct script insertion attacks
You need to log in to the Secunia Community to view the full description of this advisory
If you are not a member of the Secunia community, you can sign up here for free.
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this
information to email@example.com
Score: 0 Posts: 3 User Since: 3rd Feb 2012 System Score: N/A Location: AU Last edited on 3rd Feb, 2012 17:12
To mitigate the impact of trivial JS injection as demonstrated by Sony, public Foswiki sites which allow unmoderated user registration should customize their NewUserTemplate to restrict VIEW/CHANGE access on those new user profile topics, and also check to see if all webs (including Sandbox) have ACLs set to deny new users CHANGE permission everywhere in the wiki.
Typically, public Foswiki installations grant CHANGE permission to groups, and then add trusted users to those groups.