Drupal DrupalChat Module Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
BID:100439
Info
Drupal DrupalChat Module Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 100439 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2017 12:00AM |
| Updated: | Jul 05 2017 12:00AM |
| Credit: | Elin Yordanov |
| Vulnerable: |
Drupal DrupalChat 7.x-2.5 Drupal DrupalChat 7.x-2.4 Drupal DrupalChat 7.x-2.3 Drupal DrupalChat 7.x-2.2 Drupal DrupalChat 7.x-2.1 Drupal DrupalChat 7.x-2.0 |
| Not Vulnerable: |
Drupal DrupalChat 7.x-2.7 |
Discussion
Drupal DrupalChat Module Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
The DrupalChat module for Drupal is prone to a cross-site request-forgery vulnerability and a cross-site scripting vulnerability.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or perform unauthorized actions in the context of the affected application. Other attacks are also possible.
DrupalChat 7.x-2.x versions prior to 7.x-2.7 are vulnerable.
The DrupalChat module for Drupal is prone to a cross-site request-forgery vulnerability and a cross-site scripting vulnerability.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or perform unauthorized actions in the context of the affected application. Other attacks are also possible.
DrupalChat 7.x-2.x versions prior to 7.x-2.7 are vulnerable.
Solution / Fix
Drupal DrupalChat Module Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.