Rollbase Login XSS Vulnerability

Posted by Rollbase User on 04-Oct-2010 20:20

Hi, We discovered a major problem in the login page of Rollbase. A cross-site scripting vulnerability exists that could allow an attacker to gather username and passwords from the HTTPS login site. Where should we report this? Thanks

All Replies

Posted by Admin on 04-Oct-2010 21:46

Please submit support requests from your customer zone.

Posted by Admin on 06-Oct-2010 04:43

Thanks Pavel for the response.
We have submitted a support ticket, but have not yet received a response for more than 24 hours now.
I think this problem needs to be resolved as quickly as possible, as I have created a code that can submit login information to a third party site.

Posted by Admin on 06-Oct-2010 10:04

I have not seen your ticket. What's your company name? Anyway, I think the issue is resolved now - please try if you still can hack login page.

Posted by Admin on 07-Oct-2010 03:46

Thank you. I have submitted the support ticket to Rollbase.ph, however we have not yet received response yet. It seems that Rollbase.com's XSS problem is fixed, and I'm happy for the quick action, but the problem persists on the .PH site.

Once again, thanks!

Posted by Admin on 07-Oct-2010 09:37

It will be fixed on .ph server as well after the next update.

Posted by Admin on 12-Oct-2010 20:19

Thanks. However, we still have a problem on the Log-Out portion this time. Sorry to be a nitpicker, but there is still a XSS vulnerability on the log out page. I created script that could steal or hijack an existing user session, bypassing the need to log in. An attacker could have the same access privileges as the hacked account.

Can you please look into this? I can give the attack code if you want.

Again, a big thanks!

Posted by Admin on 12-Oct-2010 21:37

Thanks for noticing, will fix ASAP.

This thread is closed