Drupal Services Single Sign-On Client Module Cross Site Scripting Vulnerability
BID:102189
Info
Drupal Services Single Sign-On Client Module Cross Site Scripting Vulnerability
| Bugtraq ID: | 102189 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2017 12:00AM |
| Updated: | Dec 19 2017 10:01PM |
| Credit: | Scott Allison |
| Vulnerable: |
Drupal Services single sign-on client 7.x-1.x-dev Drupal Services single sign-on client 7.x-1.5 Drupal Services single sign-on client 7.x-1.4 Drupal Services single sign-on client 7.x-1.3 Drupal Services single sign-on client 7.x-1.2 Drupal Services single sign-on client 7.x-1.1 |
| Not Vulnerable: |
Drupal Services single sign-on client 7.x-1.6 |
Discussion
Drupal Services Single Sign-On Client Module Cross Site Scripting Vulnerability
The Services Single Sign-On Client module for Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied text.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Services Single Sign-On Client 7.x-1.x-dev prior to 7.x-1.6 are affected.
The Services Single Sign-On Client module for Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied text.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Services Single Sign-On Client 7.x-1.x-dev prior to 7.x-1.6 are affected.
Exploit / POC
Drupal Services Single Sign-On Client Module Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
References
Drupal Services Single Sign-On Client Module Cross Site Scripting Vulnerability
References:
References: