https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=39882

--- Comment #29 from Lucas Gass (lukeg) <[email protected]> ---
(In reply to David Cook from comment #28)
> (In reply to David Cook from comment #27)
> > Comment on attachment 204565 [details] [review] [review]
> > Bug 39882: Add ability to mask phone numbers on memberentry.pl
> > 
> > Review of attachment 204565 [details] [review] [review]:
> > -----------------------------------------------------------------
> > 
> > ::: koha-tmpl/intranet-tmpl/prog/en/modules/members/memberentrygen.tt
> > @@ +1648,5 @@
> > > +        const pattern = "[% Koha.Preference('PhoneMaskPattern') | $raw 
> > > %]";
> > > +        const fields = "[% Koha.Preference('PhoneMaskFields') | $raw %]";
> > > +
> > > +        if (pattern && fields) {
> > > +            const mask = [[% Koha.Preference('PhoneMaskPattern') | $raw 
> > > %]];
> > 
> > All these "[% Koha.Preference('PhoneMaskFields') | $raw %]" and "[%
> > Koha.Preference('PhoneMaskPattern') | $raw %]"lines are XSS vulnerabilities
> > that could lead to account takeover. Even if you were using CSP, the
> > Javascript being generated is "trusted", so a malicious payload would still
> > execute. 
> > 
> > While technically this code is meeting the JS19 coding guideline (
> > https://wiki.koha-community.org/wiki/Coding_Guidelines#JS19:_Avoid_Template::
> > Toolkit_tags_in_script_tags ), that guideline is currently incomplete, and
> > changes will be coming in the future. 
> > 
> > I'll have to take a look at the proposed patterns to see what would be the
> > appropriate filter instead of $raw...
> 
> At a glance, I think you should be able to switch to using the "html" filter
> instead of $raw, and the double quote enclosed preferences should be OK from
> there, but that last one that doesn't have quotes is a problem. If that one
> needs to contain a JSON data structure, then it needs to first be parsed as
> JSON, escaped using a "json" filter, and then subbed into that line.

Nice catch. I think this actually helps lead me a better overall solution. New
patches incoming.

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to