Skip to content

Harden Injection viewer boundaries - #261

Open
tobymoreno wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
tobymoreno:fix/dvwa-injection-viewers
Open

tobymoreno wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
tobymoreno:fix/dvwa-injection-viewers

Conversation

@tobymoreno

Copy link
Copy Markdown

Summary

  • allow-list challenge IDs, security levels, and locales before resolving help or source files
  • remove dynamic eval from help rendering and include only known local help files
  • parameterize the CSRF credential helper query and HTML-encode reflected usernames
  • add focused A05 regression coverage

OWASP mapping

  • A05:2025 Injection
  • CWE-79, CWE-89, CWE-95, CWE-98, CWE-99, CWE-610

Validation

  • PHP syntax checks pass for all five modified PHP files in the DVWA container
  • 3 focused regression tests pass
  • git diff --check passes

Allow only known challenge, security, and locale values before resolving help or source files. Remove dynamic eval from help rendering and parameterize the CSRF credential helper while encoding reflected usernames.

Signed-off-by: Toby Moreno <chris.moreno.ctr@km.spaceforce.mil>
@github-actions

github-actions Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

🏆 DVWA — CTF Patch Score

░░░░░░░░░░░░░░░░░░░░  0 / 108 pts  (0%)

0 / 55 challenges patched

Per-challenge detail is withheld — it would reveal the rubric.

Commit: 277822f · scoring run

No points yet — this commit didn't solve any challenges, so there's nothing on the leaderboard for it. Patch a vulnerability and push again! 💪

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant