webformThe Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
Webform includes a submodule called Webform Entity Print. This submodule doesn't sufficiently limit access to its print templates. When the submodule is enabled, a user with permissions to create a webform can exploit cross-site scripting (XSS) in submodule settings.
This vulnerability is mitigated by the fact that an attacker must have a role with create webform and edit own webform permissions, and the Webform Entity Print module must be enabled.
Install the latest version:
- If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
- If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Cathy Theys (yesct) of the Drupal Security Team