Video - Critical - Remote Code Execution - SA-CONTRIB-2019-037

Date: 
2019-March-13

This module provides a field where editors can add videos to their content and this module offers functionality to transcode these videos to different sizes and formats.

The module doesn't sufficiently sanitize some user input on administrative forms.

Views (for Drupal 7) - Less critical - Cross site scripting - SA-CONTRIB-2019-036

Date: 
2019-March-13

This module enables you to create customized lists of data.

The module doesn't sufficiently sanitize certain field types, leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that a view must display a field with the format "Full data (serialized)" and an attacker must have the ability to store malicious markup in that field.

Views (for Drupal 7) - Moderately critical - Information disclosure - SA-CONTRIB-2019-035

Date: 
2019-March-13

This module enables you to create customized lists of data.

The module doesn't sufficiently build queries when used with exposed filters, leading to a possible information disclosure vulnerability in certain rare circumstances.

This vulnerability is mitigated by the fact that a view must have an exposed filter on a field that is used on multiple entity types, both of which are included in the view.

Views (for Drupal 7) - Moderately critical - Information Disclosure - SA-CONTRIB-2019-034

Date: 
2019-March-13

This module enables you to create customized lists of data.

The module doesn't sufficiently protect against argument definitions failing.

This vulnerability is mitigated by the fact that a view must have custom PHP code used as a field validator.

EU Cookie Compliance (GDPR Compliance) - Critical - Cross site scripting - SA-CONTRIB-2019-033

Date: 
2019-March-06

This module addresses the General Data Protection Regulation (GDPR) that came into effect 25th May 2018, and the EU Directive on Privacy and Electronic Communications from 2012. It provides a banner where you can gather consent from the user when the website stores cookies on their computer or otherwise handles their personal information.

Ubercart - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2019-032

Date: 
2019-March-06

The Ubercart module provides a shopping cart and e-commerce features for Drupal.

The taxes module doesn't sufficiently protect the tax rate cloning feature. A malicious user could trick a store administrator into duplicating an existing tax rate by getting them to visit a specially-crafted URL.

Drupal voor Gemeenten - Moderately critical - Access Bypass - SA-CONTRIB-2019-031

Date: 
2019-March-06

The DvG distrubition contains the feature module dvg_domains to support multiple domains.

When the dvg_domains feature module is enabled, anonymous users are able to access some administration pages and change the settings exposed on those pages.

This issue can be mitigated by disabling the dvg_domains module.

Facets - Moderately critical - Cross site scripting - SA-CONTRIB-2019-030

Date: 
2019-February-27

This module enables you to create facet-filters for results of a search query and exposes them as blocks

The module doesn't sufficiently escape HTML under the scenario leading to a Cross Site Scripting (XSS) vulnerability.

Rabbit Hole - Moderately critical - Access bypass - SA-CONTRIB-2019-029

Date: 
2019-February-27

The Rabbit Hole module allows administrators to control what should happen when a regular user tries to view an entity at its own page; for example, it may deliver a 403 Access Denied or 404 Page Not Found response, or redirect the user to another path.

The module doesn't respect the Rabbit Hole settings when an entity is being requested with a certain header. This could lead to certain data being exposed even if it shouldn't be. The vulnerability is mitigated by the fact that the user also needs permission to view the content being requested.

Context - Moderately critical - Cross site scripting - SA-CONTRIB-2019-028

Date: 
2019-February-27

This module enables you to manage contextual conditions and reactions for different portions of your site.

The module doesn't sufficiently sanitize user output when displayed leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have the ability to store malicious markup in the site (e.g. permission to create a node with a field that accepts "filtered html").

Pages

Subscribe with RSS Subscribe to Security advisories