Ticket #792 (new maintenance)

Opened 2 years ago

Last modified 2 years ago

[Security-news] SA-CONTRIB-2014-094 - Webform Patched - Cross Site Scripting (XSS)

Reported by: paul Owned by: ed
Priority: major Milestone: Maintenance
Component: Drupal modules & settings Keywords:
Cc: chris Estimated Number of Hours: 0.0
Add Hours to Ticket: 0 Billable?: yes
Total Hours: 0.625

Description

View online: https://www.drupal.org/node/2344369

  • Advisory ID: DRUPAL-SA-CONTRIB-2014-094
  • Project: Webform Patched [1] (third-party module)
  • Version: 6.x, 7.x
  • Date: 2014-September-24
  • Security risk: 13/25 ( Moderately Critical)

AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]

  • Vulnerability: Cross Site Scripting


The Webform Patched module is a fork of the Webform module with Token support
added. The module enables you to create forms which can be used for surveys,
contact forms or other data collection throughout your site.

The module doesn't sufficiently sanitize field label titles when two fields
have the same form_key, which can only be managed by carefully crafting the
webform structure via a specific set of circumstances.

This vulnerability is mitigated by the fact that an attacker must have a role
with the permission "create webform content".



  • /A CVE identifier [3] will be requested, and added upon issuance, in

accordance
with Drupal Security Team processes./



  • Webform Patched 6.x-3.x versions prior to 6.x-3.20.
  • Webform Patched 7.x-3.x versions prior to 7.x-3.20.

Drupal core is not affected. If you do not use the contributed Webform
Patched [4] module,
there is nothing you need to do.



Install the latest version:

  • If you use the webform module for Drupal 6.x, upgrade to webform_patched

6.x-3.20 [5]

  • If you use the webform module for Drupal 7.x-3.x, upgrade to

webform_patched 7.x-3.20 [6]

Also see the Webform Patched [7] project page.



  • Maurits Lawende [8]
  • Matt Vance [9]


  • Nate Haug [10] the module maintainer


  • Greg Knaddison [11], Dan Smith [12] and Lee Rowlands [13] of the Drupal

Security Team



The Drupal security team can be reached at security at drupal.org or via the
contact form at
https://www.drupal.org/contact [14].

Learn more about the Drupal Security team and their policies [15],
writing secure code for Drupal [16], and
securing your site [17].

[1] https://www.drupal.org/project/webform_patched
[2] https://www.drupal.org/security-team/risk-levels
[3] http://cve.mitre.org/
[4] https://www.drupal.org/project/webform_patched
[5] http://drupal.org/node/2241675
[6] http://drupal.org/node/2241685
[7] https://www.drupal.org/project/webform_patched
[8] http://drupal.org/user/243897
[9] https://www.drupal.org/user/10269
[10] http://drupal.org/user/35821
[11] http://drupal.org/user/36762
[12] http://drupal.org/user/241220
[13] https://drupal.org/user/395439
[14] https://www.drupal.org/contact
[15] https://www.drupal.org/security-team
[16] https://www.drupal.org/writing-secure-code
[17] https://www.drupal.org/security/secure-configuration

Change History

comment:1 follow-up: ↓ 4 Changed 2 years ago by paul

  • Add Hours to Ticket changed from 0.0 to 0.25
  • Total Hours changed from 0.0 to 0.25

@Chris

My stage site is not loading. Would you investigate. Thanks.

Version 0, edited 2 years ago by paul (next)

comment:2 Changed 2 years ago by paul

Sorry, it just seems to be the update page. I'll have another look ..

https://booker-stage-20140717.transitionnetwork.org/admin/reports/updates

comment:3 Changed 2 years ago by paul

  • Add Hours to Ticket changed from 0.0 to 0.25
  • Total Hours changed from 0.25 to 0.5

Production updated.

comment:4 in reply to: ↑ 1 Changed 2 years ago by chris

  • Cc chris added
  • Add Hours to Ticket 0 deleted
  • Milestone set to Maintenance

Replying to paul:

@Chris

My stage site is not loading. Would you investigate. Thanks.

https://booker-stage-20140717.transitionnetwork.org

Hi, I only came across this ticket by looking at the timeline -- you need to add chris to the Cc box to copy tickets to me if you want me to get them by email!

In any case the site appears to be working OK now?

comment:5 Changed 2 years ago by chris

  • Component changed from Live server to Drupal modules & settings

comment:6 Changed 2 years ago by paul

  • Add Hours to Ticket changed from 0.0 to 0.125
  • Total Hours changed from 0.5 to 0.625

Roger that.

The problem was just that the update module was disabled on my stage site. I have enabled updates and database logging. All good.

Last edited 2 years ago by paul (previous) (diff)
Note: See TracTickets for help on using tickets.