Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2015-081
HistoryMar 25, 2015 - 12:00 a.m.

Petition - Moderately Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2015-081

2015-03-2500:00:00
Drupal Security Team
www.drupal.org
3

CVSS2

2.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:N/I:P/A:N

EPSS

0.967

Percentile

99.7%

The Petition module enables you to create petitions which users may sign.

The module doesn’t sufficiently sanitize user supplied text in some administration pages, thereby exposing a Cross Site Scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission “create petition”.

CVE identifier(s) issued

  • CVE-2015-4377

Versions affected

  • Petition 6.x-1.x versions prior to 6.x-1.3.

Drupal core is not affected. If you do not use the contributed Petition module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Petition module for Drupal 6.x, upgrade to Petition 6.x-1.3

Also see the Petition project page.

Reported by

Fixed by

Coordinated by

CVSS2

2.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:N/I:P/A:N

EPSS

0.967

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2015-081