Closed (fixed)
Project:
Homebox - Individual user dashboards
Version:
6.x-2.x-dev
Component:
Code
Priority:
Critical
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
13 May 2010 at 13:57 UTC
Updated:
5 Jun 2010 at 14:50 UTC
Hi again,
I was looking through the JS code, specifically, the data that is returned regarding the user settings. When the block data makes it to the server, it looks like there's no check to make sure that the returned blocks are part of the default page. I could be wrong, but it looks like someone could modify the DOM with data about other blocks in the system, and have them returned.
I haven't checked yet - but it seems possible...
Comments
Comment #1
mstef commentedDoesn't seem like you check to see if colors are allowed either...less of a security risk..
Comment #2
mstef commentedSee #794728: Re-engineering & Improving Home Box (Exportables, Performance, Features, etc)
Comment #3
mstef commented