magento / magento2

Prior to making any Submission(s), you must sign an Adobe Contributor License Agreement, available here at: https://opensource.adobe.com/cla.html. All Submissions you make to Adobe Inc. and its affiliates, assigns and subsidiaries (collectively “Adobe”) are subject to the terms of the Adobe Contributor License Agreement.
http://www.magento.com
Open Software License 3.0
11.46k stars 9.28k forks source link

Wishlist sharing form allows random code in the name fields #39024

Open ganeddact opened 1 month ago

ganeddact commented 1 month ago

Preconditions and environment

Steps to reproduce

  1. Install a fresh Magento latest version with sample data
  2. Register as a customer and login
  3. Add a product to the wishlist
  4. Click to share the wishlist
  5. Add the following code to the wishlist share message: {{var this.getTempl%0d%0aateFilter().filter(%22ls -al%22)}}{{if this.getTempla%0d%0ateFilter().addAft%0d%0aerFilterCallback(%22SySTeM%22).filter(%22ls -al%22)}}{{/if}}

Expected result

Magento should block the sending of this type of text and not allow template injection

Actual result

An email with the code is fired out with no error raised

Additional information

It's a sister issue of https://github.com/magento/magento2/issues/38331 and https://github.com/magento/magento2/issues/39002

Release note

No response

Triage and priority

m2-assistant[bot] commented 1 month ago

Hi @ganeddact. Thank you for your report. To speed up processing of this issue, make sure that the issue is reproducible on the vanilla Magento instance following Steps to reproduce. To deploy vanilla Magento instance on our environment, Add a comment to the issue:

ganeddact commented 1 month ago

@magento give me 2.4-develop instance

magento-deployment-service[bot] commented 1 month ago

Hi @ganeddact. Thank you for your request. I'm working on Magento instance for you.

magento-deployment-service[bot] commented 1 month ago

Hi @ganeddact, here is your Magento Instance: https://a896b45b2fc43dee6a7d8360a5c35270.instances-prod.magento-community.engineering Admin access: https://a896b45b2fc43dee6a7d8360a5c35270.instances-prod.magento-community.engineering/admin_f160 Login: 910b7af8 Password: 0da1d1f732c6

m2-assistant[bot] commented 1 month ago

Hi @engcom-Bravo. Thank you for working on this issue. In order to make sure that issue has enough information and ready for development, please read and check the following instruction: :point_down:

ganeddact commented 1 month ago

The Magento instance doesn't allow to send emails from either wishlist sharing or contact page, is it turned off at server level?

ganeddact commented 1 month ago

This is what I get on our private test magento instance (on 2.4.6-p6) Screenshot 2024-08-08 at 11 52 14 and the email: Screenshot 2024-08-08 at 11 53 51

engcom-Bravo commented 1 month ago

Hi @ganeddact,

Thanks for your reporting and collaboration.

We have verified the issue in Latest 2.4-develop instance and the issue is reproducible.kindly refer the screenshots.

Steps to reproduce

Screenshot 2024-08-09 at 10 50 53

There is no error raised while sharing the wishlist.

Hence Confirming the issue.

Thanks.

github-jira-sync-bot commented 1 month ago

:white_check_mark: Jira issue https://jira.corp.adobe.com/browse/AC-12730 is successfully created for this GitHub issue.

m2-assistant[bot] commented 1 month ago

:white_check_mark: Confirmed by @engcom-Bravo. Thank you for verifying the issue.
Issue Available: @engcom-Bravo, You will be automatically unassigned. Contributors/Maintainers can claim this issue to continue. To reclaim and continue work, reassign the ticket to yourself.