Sec Bug->Bug #81743 [Opn->Wfx]: XSS via PDOException error
| From: | cmb@php.net | Date: | Mon, 12 Dec 2022 17:02:00 +0000 |
| Subject: | Sec Bug->Bug #81743 [Opn->Wfx]: XSS via PDOException error | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-243112@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81743&edit=1
ID: 81743
Updated by: cmb@php.net
Reported by: elbrinsomar666 at gmail dot com
Summary: XSS via PDOException error
-Status: Open
+Status: Wont fix
-Type: Security
+Type: Bug
Package: PDO Core
Operating System: *
PHP Version: 8.1.13
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: Y
New Comment:
This might require display_errors to be on, but the documentation
states[1]:
| This is a feature to support your development and should never
| be used on production systems (e.g. systems connected to the
| internet).
> that this malicious XSS is executed at developers or an admin
> panel that will review this PDOException
If a PHP log file is (partially) displayed in an admin panel, it
needs to be properly escaped, like every other output, by the PHP
userland developer. The same escaping needs to be done, if an
exception message is echoed.
So no, this is not a security issue. And especially the echoing
is nothing we can fix, because that very same code may run on the
command line, where applying HTML escaping would just be wrong.
[1] <https://www.php.net/manual/en/errorfunc.configuration.php#ini.display-errors>
Previous Comments:
------------------------------------------------------------------------
[2022-12-12 15:41:06] elbrinsomar666 at gmail dot com
Description:
------------
There is an XSS through PDOException error as if the user input was like that
HTTP://localhost/vulnerable-script.php?q=/<script>alert(document.cookie)</script>
you will find that there is an error generated
"Exception : SQLSTATE[42000]: Syntax error or access violation: 1064 You have an error in your
SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to
use near '/<script>alert(document.cookie)</script>' at line 1"
which is the error message you will find that the user malicious input is reflected without any type
of encoding (e.g. HTML entity encoding) which will lead from the error message to allowing a
malicious user to execute javascript code to steal the victims cookie or execute malicious
javascript code
Notes:
1- I know that this code is vulnerable to SQL injection but just assume that there is validation
used by developers to prevent SQL Injection
2- I will use MySQL database as an example but I tested this vulnerability on SQLite too which
obviously means that this vulnerability is on the PDO core and not related to a specific database
3- Tested on PHP version 8 and PHP version 5 but i didn't test it on versions between PHP8 and
PHP5 yet
Test script:
---------------
<?php
$dsn = 'mysql:host=localhost;dbname=LoginSystem';
$db = new PDO($dsn, 'username', 'password');
try {
$q = $_GET['q'];
$stmt = $db->query("SELECT * FROM users WHERE id=$q");
} catch (PDOException $e) {
print 'Exception : '.$e->getMessage();
}
?>
Expected result:
----------------
The above code is a common example of how developers use PDOException to trace errors or log them so
the expected result is that the $e->getMessage() method should print PDOException as HTML entity
encoded
Impact: As I described if the input is reflected it will lead to Reflected XSS but a lot of times
developers uses this method to log exception so imagine that this malicious XSS is executed at
developers or an admin panel that will review this PDOException it will lead to critical impact if
attacker stole developers or admins cookies with Blind XSS
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81743&edit=1