Drupal AddonChat Module Privilege Escalation and HTML Injection Vulnerabilities
BID:40393
Info
Drupal AddonChat Module Privilege Escalation and HTML Injection Vulnerabilities
| Bugtraq ID: | 40393 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2010 12:00AM |
| Updated: | May 26 2010 12:00AM |
| Credit: | Jonathan Hedstrom; Dylan Tack of the Drupal Security Team |
| Vulnerable: |
Drupal AddonChat 6.x-1.0 |
| Not Vulnerable: |
Drupal AddonChat 6.x-1.2 |
Discussion
Drupal AddonChat Module Privilege Escalation and HTML Injection Vulnerabilities
The AddonChat module for Drupal is prone to a privilege-escalation vulnerability and multiple HTML-injection vulnerabilities.
Attackers can leverage the privilege-escalation issue to log in as a legitimate user with elevated privileges.
Additionally, exploiting the HTML-injection issues allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
To exploit any of the HTML-injection issues, attackers must have 'access administration pages' permissions.
Versions prior to AddonChat 6.x-1.2 are vulnerable.
The AddonChat module for Drupal is prone to a privilege-escalation vulnerability and multiple HTML-injection vulnerabilities.
Attackers can leverage the privilege-escalation issue to log in as a legitimate user with elevated privileges.
Additionally, exploiting the HTML-injection issues allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
To exploit any of the HTML-injection issues, attackers must have 'access administration pages' permissions.
Versions prior to AddonChat 6.x-1.2 are vulnerable.
Exploit / POC
Drupal AddonChat Module Privilege Escalation and HTML Injection Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Drupal AddonChat Module Privilege Escalation and HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Drupal AddonChat 6.x-1.0
Solution:
Updates are available. Please see the references for details.
Drupal AddonChat 6.x-1.0
-
Drupal addonchat-6.x-1.2.tar.gz
http://ftp.drupal.org/files/projects/addonchat-6.x-1.2.tar.gz
References
Drupal AddonChat Module Privilege Escalation and HTML Injection Vulnerabilities
References:
References: