Drupal RedHen CRM Module Cross Site Scripting Vulnerability
BID:69348
Info
Drupal RedHen CRM Module Cross Site Scripting Vulnerability
| Bugtraq ID: | 69348 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 20 2014 12:00AM |
| Updated: | Aug 20 2014 12:00AM |
| Credit: | Matt Vance |
| Vulnerable: |
Drupal RedHen CRM 7.x-1.0 |
| Not Vulnerable: |
Drupal RedHen CRM 7.x-1.8 |
Discussion
Drupal RedHen CRM Module Cross Site Scripting Vulnerability
The RedHen CRM module for Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials.
The RedHen CRM module for Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials.
Exploit / POC
Drupal RedHen CRM Module Cross Site Scripting Vulnerability
To exploit this issue the attacker needs to entice a user into following a malicious URI.
To exploit this issue the attacker needs to entice a user into following a malicious URI.
References
Drupal RedHen CRM Module Cross Site Scripting Vulnerability
References:
References:
- Drupal Homepage (Drupal)
- SA-CONTRIB-2013-079 - RedHen CRM - Cross Site Scripting (XSS) (Drupal)