Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2012-013
HistoryJan 25, 2012 - 12:00 a.m.

SA-CONTRIB-2012-013 - Search Autocomplete - SQL Injection

2012-01-2500:00:00
Drupal Security Team
www.drupal.org
2

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

0.003 Low

EPSS

Percentile

66.0%

CVE: CVE-2012-1638

The Search Autocomplete module allows you to add autocomplete functionality to the search fields of a Drupal site.

Search Autocomplete does not properly use Drupal’s database API, making it possible for a malicious user to carryout SQL injection on the site. This vulnerability is mitigated by the fact that users must have a role with permission “use search_autocomplete” to exploit.

Versions affected

  • Search Autocomplete versions prior to 7.x-2.1.

Drupal core is not affected. If you do not use the contributed Search Autocomplete module, there is nothing you need to do.

Solution

Install the latest version:

See the Search Autocomplete project page for more information.

Reported by

Fixed by

Coordinated by

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

0.003 Low

EPSS

Percentile

66.0%

Related for DRUPAL-SA-CONTRIB-2012-013