oss-sec mailing list archives

CVE request for Ushahidi


From: Robbie MacKay <robbie () ushahidi com>
Date: Tue, 31 Jul 2012 12:22:16 +1200

The Ushahidi team have been notified of the following security
vulnerabilities thanks to volunteers from OWASP Portland.
These will be fixed in the upcoming 2.5 release.
Could you please allocate CVEs for the following issues?

* Multiple SQL injections (Reported by Timothy D. Morgan, Kees Cook,
postmodern )
https://github.com/ushahidi/Ushahidi_Web/commit/fdb48d1
https://github.com/ushahidi/Ushahidi_Web/commit/6f6a919
https://github.com/ushahidi/Ushahidi_Web/commit/4764792
https://github.com/ushahidi/Ushahidi_Web/commit/d954093
https://github.com/ushahidi/Ushahidi_Web/commit/3301e48
https://github.com/ushahidi/Ushahidi_Web/commit/68d9916
https://github.com/ushahidi/Ushahidi_Web/commit/e0e2b66
https://github.com/ushahidi/Ushahidi_Web/commit/a11d43c
https://github.com/ushahidi/Ushahidi_Web/commit/3f14fa0

* Missing authentication on comments, reports, email API calls
(Reported by Kees
Cook, Dennison Williams)
https://github.com/ushahidi/Ushahidi_Web/commit/4c24325
https://github.com/ushahidi/Ushahidi_Web/commit/f67f4ad

* User details exposed in comments API (Discovered by internal dev team)
https://github.com/ushahidi/Ushahidi_Web/commit/529f353

* Admin user hijacking through the installer (Reported by Wil Clouser)
https://github.com/ushahidi/Ushahidi_Web/commit/7892559
https://github.com/ushahidi/Ushahidi_Web/commit/fcdad03

* Stored XSS on member profile pages (Reported by Amy K. Farrell)
https://github.com/ushahidi/Ushahidi_Web/commit/00eae4f

Thanks in advance,

Robbie Mackay

Software Developer, External Projects
Ushahidi Inc
e: robbie () ushahidi com
skype: robbie.mackay

Current thread: