2.1 Low
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:H/Au:S/C:N/I:P/A:N
0.967 High
EPSS
Percentile
99.7%
CVE: CVE-2012-2070
The MultiBlock module allows an administrator to create multiple instances of blocks provided by other modules. The module does not properly sanitize the block title provided by a block administrator, leading to a cross-site scripting (XSS) vulnerability. Such an attack may lead to a malicious user gaining full administrative access. A user must have a role with the permission ‘administer blocks’ to exploit this vulnerability.
Drupal core is not affected. If you do not use the contributed MultiBlock module, there is nothing you need to do.
Install the latest version:
Also see the MultiBlock project page.
drupal.org/contact
drupal.org/node/1505410
drupal.org/node/1505414
drupal.org/project/multiblock
drupal.org/security-team
drupal.org/security-team/risk-levels
drupal.org/security/secure-configuration
drupal.org/user/102818
drupal.org/user/302225
drupal.org/user/383424
drupal.org/user/49940
drupal.org/writing-secure-code