Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2013-007
HistoryJan 23, 2013 - 12:00 a.m.

SA-CONTRIB-2013-007 User Relationships - Cross Site Scripting (XSS)

2013-01-2300:00:00
Drupal Security Team
www.drupal.org
7

2.1 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:N/I:P/A:N

0.001 Low

EPSS

Percentile

39.9%

The User Relationships module allows you to create multiple relationship types and maintain relationships between users in your Drupal site.

The module does not sufficiently escape relationship names before display. This allows users with the correct permissions to create relationship names containing arbitrary Javascript which will then be executed by the browser.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer user relationships”.

CVE identifier(s) issued

  • CVE-2013-0225

Versions affected

  • User Relationships 6.x-1.x versions prior to 6.x-1.4
  • User Relationships 7.x-1.x versions prior to 7.x-1.0-alpha5

Drupal core is not affected. If you do not use the contributed User Relationships module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the User Relationships module for Drupal 6.x, upgrade to User Relationships 6.x-1.4
  • If you use the User Relationships module for Drupal 7.x, upgrade to User Relationships 7.x-1.0-alpha5

Also see the User Relationships project page.

Reported by

Fixed by

Coordinated by

2.1 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:N/I:P/A:N

0.001 Low

EPSS

Percentile

39.9%

Related for DRUPAL-SA-CONTRIB-2013-007