Since _captcha_get_posted_captcha_info uses raw #post data (not $form_state['values']), user can pass arbitrary data (i.e. script in $_POST['captcha_sid']) and get it back from drupal - which exposes XSS probability.
Attached patch fixes the problem by adding very simple check

Comments

Status: Needs review » Needs work

The last submitted patch, captcha-2.2.XSS_.patch, failed testing.

soxofaan’s picture

Title: XSS in captcha_sid » filter raw post data before usage (XSS)
Version: 6.x-2.2 » 6.x-2.x-dev
Assigned: valthebald » soxofaan
Status: Needs work » Needs review
Issue tags: +xss
StatusFileSize
new1.39 KB

The cast to int was already added to CVS (issue: #810534: Fix CAPTCHA session reuse)

nevertheless, attached patch adds an additional touch of paranoia

Status: Needs review » Needs work

The last submitted patch, 934450_filter_raw_post_data_01.patch, failed testing.

soxofaan’s picture

Status: Needs work » Needs review
StatusFileSize
new1.99 KB

fixed regexp

soxofaan’s picture

Version: 6.x-2.x-dev » 7.x-1.x-dev
Status: Needs review » Patch (to be ported)
Issue tags: +low-hanging fruit

fixed for D6 by http://drupal.org/cvs?commit=439172

To be ported to D7? Not necessarily, because _captcha_get_posted_captcha_info() can be simplified in D7 possibly.

soxofaan’s picture

Status: Patch (to be ported) » Fixed

code was included in D7 port
so fixed

Status: Fixed » Closed (fixed)
Issue tags: -low-hanging fruit, -xss

Automatically closed -- issue fixed for 2 weeks with no activity.