Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2012-096
HistoryJun 06, 2012 - 12:00 a.m.

SA-CONTRIB-2012-096 - Authoring HTML - Cross Site Scripting (XSS)

2012-06-0600:00:00
Drupal Security Team
www.drupal.org
4

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

0.967 High

EPSS

Percentile

99.7%

This module creates an input format suitable for use within a WYSIWYG editor. It adds support for the iframe HTML tag, making it friendly with the popular iframe embeds available in popular video sites like YouTube and Vimeo. It supports the script tag too. Both tags will only be allowed if the referred URL is whitelisted. By default, you can refer some well known video sites in the iframe tag and any site with the <script> tag.

The module doesn’t sufficiently verify the whitelisted hosts. This allows an attacker to register and use a malicious host, bypassing verification.

This vulnerability is mitigated by the fact that an attacker must have a role authorized to use the “Authoring HTML” input format.

CVE: CVE-2012-2725

Versions affected

  • Authoring HTML 6.x-1.x versions prior to 6.x-1.1.

Drupal core is not affected. If you do not use the contributed Authoring HTML module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Authoring HTML project page.

Reported by

Fixed by

Coordinated by

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

0.967 High

EPSS

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2012-096