Ticket #792 (new maintenance)
[Security-news] SA-CONTRIB-2014-094 - Webform Patched - Cross Site Scripting (XSS)
Reported by: | paul | Owned by: | ed |
---|---|---|---|
Priority: | major | Milestone: | Maintenance |
Component: | Drupal modules & settings | Keywords: | |
Cc: | chris | Estimated Number of Hours: | 0.0 |
Add Hours to Ticket: | 0 | Billable?: | yes |
Total Hours: | 0.625 |
Description
View online: https://www.drupal.org/node/2344369
- Advisory ID: DRUPAL-SA-CONTRIB-2014-094
- Project: Webform Patched [1] (third-party module)
- Version: 6.x, 7.x
- Date: 2014-September-24
- Security risk: 13/25 ( Moderately Critical)
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
- Vulnerability: Cross Site Scripting
The Webform Patched module is a fork of the Webform module with Token support
added. The module enables you to create forms which can be used for surveys,
contact forms or other data collection throughout your site.
The module doesn't sufficiently sanitize field label titles when two fields
have the same form_key, which can only be managed by carefully crafting the
webform structure via a specific set of circumstances.
This vulnerability is mitigated by the fact that an attacker must have a role
with the permission "create webform content".
- /A CVE identifier [3] will be requested, and added upon issuance, in
accordance
with Drupal Security Team processes./
- Webform Patched 6.x-3.x versions prior to 6.x-3.20.
- Webform Patched 7.x-3.x versions prior to 7.x-3.20.
Drupal core is not affected. If you do not use the contributed Webform
Patched [4] module,
there is nothing you need to do.
Install the latest version:
- If you use the webform module for Drupal 6.x, upgrade to webform_patched
6.x-3.20 [5]
- If you use the webform module for Drupal 7.x-3.x, upgrade to
webform_patched 7.x-3.20 [6]
Also see the Webform Patched [7] project page.
- Nate Haug [10] the module maintainer
Security Team
The Drupal security team can be reached at security at drupal.org or via the
contact form at
https://www.drupal.org/contact [14].
Learn more about the Drupal Security team and their policies [15],
writing secure code for Drupal [16], and
securing your site [17].
[1] https://www.drupal.org/project/webform_patched
[2] https://www.drupal.org/security-team/risk-levels
[3] http://cve.mitre.org/
[4] https://www.drupal.org/project/webform_patched
[5] http://drupal.org/node/2241675
[6] http://drupal.org/node/2241685
[7] https://www.drupal.org/project/webform_patched
[8] http://drupal.org/user/243897
[9] https://www.drupal.org/user/10269
[10] http://drupal.org/user/35821
[11] http://drupal.org/user/36762
[12] http://drupal.org/user/241220
[13] https://drupal.org/user/395439
[14] https://www.drupal.org/contact
[15] https://www.drupal.org/security-team
[16] https://www.drupal.org/writing-secure-code
[17] https://www.drupal.org/security/secure-configuration
Change History
comment:1 follow-up: ↓ 4 Changed 2 years ago by paul
- Add Hours to Ticket changed from 0.0 to 0.25
- Total Hours changed from 0.0 to 0.25
comment:2 Changed 2 years ago by paul
Sorry, it just seems to be the update page. I'll have another look ..
https://booker-stage-20140717.transitionnetwork.org/admin/reports/updates
comment:3 Changed 2 years ago by paul
- Add Hours to Ticket changed from 0.0 to 0.25
- Total Hours changed from 0.25 to 0.5
Production updated.
comment:4 in reply to: ↑ 1 Changed 2 years ago by chris
- Cc chris added
- Add Hours to Ticket 0 deleted
- Milestone set to Maintenance
Replying to paul:
@Chris
My stage site is not loading. Would you investigate. Thanks.
Hi, I only came across this ticket by looking at the timeline -- you need to add chris to the Cc box to copy tickets to me if you want me to get them by email!
In any case the site appears to be working OK now?
comment:5 Changed 2 years ago by chris
- Component changed from Live server to Drupal modules & settings
@Chris
My stage site is not loading. Would you investigate. Thanks.