Fix: Stored XSS in profile display name consent logs and IDOR in quiz builder question deletion - #3032
Closed
shewa12 wants to merge 1 commit into
Closed
Fix: Stored XSS in profile display name consent logs and IDOR in quiz builder question deletion#3032shewa12 wants to merge 1 commit into
shewa12 wants to merge 1 commit into
Conversation
… builder question deletion
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR resolves two critical security vulnerabilities:
Authenticated Stored Cross-Site Scripting (XSS) in Profile Display Name & Consent Logs
classes/Student.php,GDPR/Controllers/UserConsent.php,assets/src/js/admin-dashboard/segments/consent-logs.js, andassets/src/js/admin-dashboard/segments/students.js.display_name,first_name,last_name), standard sanitization retains HTML entity sequences. When these values are rendered into HTML data attributes (such asdata-user-name) in consent logs, browserdataset.userNameaccess automatically decodes entities. Injecting this unescaped string directly intomodalBody.innerHTMLcauses script execution in the admin dashboard context.wp_strip_all_tags( wp_specialchars_decode( ..., ENT_QUOTES ) )inStudent.phpandUserConsent.php.innerHTMLwith safe DOMtextContentassignment inconsent-logs.jsandstudents.js.Insecure Direct Object Reference (IDOR) in Quiz Builder Question & Answer Deletion
classes/QuizBuilder.php.QuizBuilder::handle_delete()executed SQL deletions fordeleted_question_idsanddeleted_answer_idswithout verifying that the targets belong to the quiz or course being edited. An authenticated instructor could submit question or answer IDs belonging to quizzes from other courses/instructors and have them deleted.tutor_utils()->can_user_manage( "quiz", $quiz_id )invalidate_payload().handle_delete()with$quiz_id, filtering deleted question IDs and answer IDs to ensure they strictly belong to the quiz being updated before executing database deletion queries.