Re: Security Bug on pgadmin 4 6.12
От | Akshay Joshi |
---|---|
Тема | Re: Security Bug on pgadmin 4 6.12 |
Дата | |
Msg-id | CANxoLDdpdmQP19tvV7T2Wg=xcEtjseOwO-8NRb2bUrRRaL+PGA@mail.gmail.com обсуждение исходный текст |
Ответ на | Re: Security Bug on pgadmin 4 6.12 (Aditya Toshniwal <aditya.toshniwal@enterprisedb.com>) |
Список | pgadmin-hackers |
On Mon, Aug 22, 2022 at 3:30 PM Aditya Toshniwal <aditya.toshniwal@enterprisedb.com> wrote:
Thank you for reporting this. We will fix this before the next release.Please report it here - https://redmine.postgresql.org/projects/pgadmin4/issues/new
We have committed the fix.
On Mon, Aug 22, 2022 at 3:03 PM Khoa Bùi Đức Anh <khoabda305@gmail.com> wrote:Hi team I found a XSS vulnerabillity on the latest pgAdmin4 (6.12).
Step by step
Bug is at API /browser/server/obj/7/
Object -> Register -> Server -> ConnectionFill in Hostname/address value ss"><iframe src=javascript:alert(document.domain)>
Click save, XSS firedAnymore information, you can ask meThanks
khoabda--Thanks,Aditya ToshniwalpgAdmin Hacker | Software Architect | edbpostgres.com"Don't Complain about Heat, Plant a TREE"
Akshay Joshi Principal Software Architect +91 9767888246 | |
В списке pgadmin-hackers по дате отправления: