Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2013-004
HistoryJan 16, 2012 - 12:00 a.m.

SA-CONTRIB-2013-004 - Live CSS - Arbitrary Code Execution

2012-01-1600:00:00
Drupal Security Team
www.drupal.org
3

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

0.01 Low

EPSS

Percentile

83.9%

This module enables you to save CSS and LESS files on the server via your browser.

The module doesn’t check that the file being saved isn’t a script or executable.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer CSS”.

CVE identifier(s) issued

  • CVE-2013-0206

Versions affected

  • Live CSS 6.x-2.x versions prior to 6.x-2.1.
  • Live CSS 7.x-2.x versions prior to 7.x-2.7.

Drupal core is not affected. If you do not use the contributed Live CSS module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Live CSS module for Drupal 6.x, upgrade to 6.x-2.1.
  • If you use the Live CSS module for Drupal 7.x, upgrade to 7.x-2.7.

Also see the Live CSS project page.

Reported by

Fixed by

Coordinated by

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

0.01 Low

EPSS

Percentile

83.9%

Related for DRUPAL-SA-CONTRIB-2013-004