Custom Tokens - Critical - Arbitrary PHP code execution - SA-CONTRIB-2018-041

Date: 
2018-June-13

The Custom Tokens module enables you to create custom tokens for specific replacements that can improve other modules relying on the token API.

The module doesn't sufficiently identify that its custom permissions are risky and should only be granted to highly trusted roles.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer custom tokens".

Entity Delete - Critical - Multiple Vulnerabilities - SA-CONTRIB-2018-040

Date: 
2018-June-06

This module enables you to delete any types of entities in bulk.

The module doesn't sufficiently verify access permissions under its use cases, leading to access bypass. The module also does not protect against Cross Site Request Forgeries on its delete process.

The access bypass vulnerability is mitigated by the fact that an attacker must have a role with the permission "access content". There is no additional mitigation for the Cross Site Request Forgery vulnerability.

AdTego SiteIntel - AdBlocker Detect - Critical - Unsupported - SA-CONTRIB-2018-039

Date: 
2018-June-06

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466.

Mollom - Critical - Unsupported - SA-CONTRIB-2018-038

Date: 
2018-June-06

The security team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported projects critical by default.

Zircon - Critical - Unsupported - SA-CONTRIB-2018-037

Date: 
2018-May-23

Update - 2018-09-26

This maintainer has fixed this security issue. Please install https://www.drupal.org/project/zircon/releases/7.x-1.2 to resolve the issue.


The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

Education - Critical - Unsupported - SA-CONTRIB-2018-036

Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

TB Sirate - Critical - Unsupported - SA-CONTRIB-2018-035

Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

Hotel - Critical - Unsupported - SA-CONTRIB-2018-034

Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

iShopping - Critical - Unsupported - SA-CONTRIB-2018-033

Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

Corporate Site - Critical - Unsupported - SA-CONTRIB-2018-032

Date: 
2018-May-23

The security team is marking this theme unsupported. There is a known security issue with the theme that has not been fixed by the maintainer. If you would like to maintain this theme, please read: https://www.drupal.org/node/251466.

The security team marks all unsupported themes and modules critical by default.

Pages

Subscribe with RSS Subscribe to Security advisories