3.5 Low
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:S/C:N/I:P/A:N
0.967 High
EPSS
Percentile
99.7%
This module creates an input format suitable for use within a WYSIWYG editor. It adds support for the iframe
HTML tag, making it friendly with the popular iframe
embeds available in popular video sites like YouTube and Vimeo. It supports the script
tag too. Both tags will only be allowed if the referred URL is whitelisted. By default, you can refer some well known video sites in the iframe
tag and any site with the <script>
tag.
The module doesn’t sufficiently verify the whitelisted hosts. This allows an attacker to register and use a malicious host, bypassing verification.
This vulnerability is mitigated by the fact that an attacker must have a role authorized to use the “Authoring HTML” input format.
CVE: CVE-2012-2725
Drupal core is not affected. If you do not use the contributed Authoring HTML module, there is nothing you need to do.
Install the latest version:
Also see the Authoring HTML project page.