Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2015-018
HistoryJan 14, 2015 - 12:00 a.m.

SA-CONTRIB-2015-018 - Video - Cross Site Scripting (XSS)

2015-01-1400:00:00
Drupal Security Team
www.drupal.org
6

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.967

Percentile

99.7%

This module enables you to upload, convert and playback videos.

The module doesn’t sufficiently sanitize node titles when using the video WYSIWYG plugin, thereby opening a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission “create video nodes” and that WYSIWYG video plugin must be enabled.

CVE identifier(s) issued

  • CVE-2015-3362

Versions affected

  • Video 7.x-2.x versions from 7.x-2.2-beta1 to 7.x-2.10.

Drupal core is not affected. If you do not use the contributed Video module,
there is nothing you need to do.

Solution

Install the latest version:

  • If you use the video module for Drupal 7.x-2.x, upgrade to Video 7.x-2.11

Also see the Video project page.

Reported by

  • Pere Orga provisional member of the Drupal Security Team

Fixed by

Coordinated by

  • Pere Orga provisional member of the Drupal Security Team

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.967

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2015-018