Sec Bug->Bug #81743 [Opn->Wfx]: XSS via PDOException error

From: Date: Mon, 12 Dec 2022 17:02:00 +0000
Subject: Sec Bug->Bug #81743 [Opn->Wfx]: XSS via PDOException error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243112@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81743&edit=1 ID: 81743 Updated by: cmb@php.net Reported by: elbrinsomar666 at gmail dot com Summary: XSS via PDOException error -Status: Open +Status: Wont fix -Type: Security +Type: Bug Package: PDO Core Operating System: * PHP Version: 8.1.13 -Assigned To: +Assigned To: cmb Block user comment: N Private report: Y New Comment: This might require display_errors to be on, but the documentation states[1]: | This is a feature to support your development and should never | be used on production systems (e.g. systems connected to the | internet). > that this malicious XSS is executed at developers or an admin > panel that will review this PDOException If a PHP log file is (partially) displayed in an admin panel, it needs to be properly escaped, like every other output, by the PHP userland developer. The same escaping needs to be done, if an exception message is echoed. So no, this is not a security issue. And especially the echoing is nothing we can fix, because that very same code may run on the command line, where applying HTML escaping would just be wrong. [1] <https://www.php.net/manual/en/errorfunc.configuration.php#ini.display-errors> Previous Comments: ------------------------------------------------------------------------ [2022-12-12 15:41:06] elbrinsomar666 at gmail dot com Description: ------------ There is an XSS through PDOException error as if the user input was like that HTTP://localhost/vulnerable-script.php?q=/<script>alert(document.cookie)</script> you will find that there is an error generated "Exception : SQLSTATE[42000]: Syntax error or access violation: 1064 You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near '/<script>alert(document.cookie)</script>' at line 1" which is the error message you will find that the user malicious input is reflected without any type of encoding (e.g. HTML entity encoding) which will lead from the error message to allowing a malicious user to execute javascript code to steal the victims cookie or execute malicious javascript code Notes: 1- I know that this code is vulnerable to SQL injection but just assume that there is validation used by developers to prevent SQL Injection 2- I will use MySQL database as an example but I tested this vulnerability on SQLite too which obviously means that this vulnerability is on the PDO core and not related to a specific database 3- Tested on PHP version 8 and PHP version 5 but i didn't test it on versions between PHP8 and PHP5 yet Test script: --------------- <?php $dsn = 'mysql:host=localhost;dbname=LoginSystem'; $db = new PDO($dsn, 'username', 'password'); try { $q = $_GET['q']; $stmt = $db->query("SELECT * FROM users WHERE id=$q"); } catch (PDOException $e) { print 'Exception : '.$e->getMessage(); } ?> Expected result: ---------------- The above code is a common example of how developers use PDOException to trace errors or log them so the expected result is that the $e->getMessage() method should print PDOException as HTML entity encoded Impact: As I described if the input is reflected it will lead to Reflected XSS but a lot of times developers uses this method to log exception so imagine that this malicious XSS is executed at developers or an admin panel that will review this PDOException it will lead to critical impact if attacker stole developers or admins cookies with Blind XSS ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81743&edit=1

« previous php.bugs (#243112) next »