Drupal Project Issue File Review Module HTML Injection Vulnerability
BID:65830
Info
Drupal Project Issue File Review Module HTML Injection Vulnerability
| Bugtraq ID: | 65830 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8765 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2014 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Wim Leers and Jeremy Thorson |
| Vulnerable: |
Drupal Project Issue File Review 6.x-2.16 Drupal Project Issue File Review 6.X-2.0 |
| Not Vulnerable: |
Drupal Project Issue File Review 6.x-2.17 |
Discussion
Drupal Project Issue File Review Module HTML Injection Vulnerability
The Project Issue File Review module for Drupal is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Project Issue File Review 6.x-2.0 versions prior to 6.x-2.17 are vulnerable.
The Project Issue File Review module for Drupal is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Project Issue File Review 6.x-2.0 versions prior to 6.x-2.17 are vulnerable.
Exploit / POC
Drupal Project Issue File Review Module HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
References
Drupal Project Issue File Review Module HTML Injection Vulnerability
References:
References: