CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
Percentile
99.7%
The Webform module enables you to create forms which can be used for surveys, contact forms or other data collection throughout your site.
The module doesn’t sufficiently sanitize field label titles when two fields have the same form_key, which can only be managed by carefully crafting the webform structure via a specific set of circumstances.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission “create webform content”.
Drupal core is not affected. If you do not use the contributed Webform module, there is nothing you need to do.
Install the latest version:
Also see the Webform project page.
drupal.org/contact
drupal.org/node/2194175
drupal.org/node/2194181
drupal.org/node/2194183
drupal.org/project/webform
drupal.org/security-team
drupal.org/security-team/risk-levels
drupal.org/security/secure-configuration
drupal.org/user/241220
drupal.org/user/243897
drupal.org/user/35821
drupal.org/writing-secure-code
drupal.org/user/395439
twitter.com/drupalsecurity