This page displays all public Tag1 D7ES announcements, including security advisories and compatibility updates. You may filter below by announcement type, project, and subscribe to that customized RSS feed at the bottom of the page.

 

Services - Moderately Critical - Stored Cross Site Scripting via Unvalidated File Uploads

Date
Severity
Moderately Critical
Affected versions
<7.x-3.30
The REST API file upload endpoints validate files by extension only, so an authenticated user can store a non-image file (such as HTML containing JavaScript) with an image extension and later reference it from an image field, leading to stored cross site scripting.

Open Atrium Notifications - Moderately Critical - Cross Site Scripting

Date
Severity
Moderately Critical
Affected versions
<7.x-2.36
The Open Atrium Notifications view template prints real names and group or team titles into an HTML title attribute without sanitization. A user who sets a crafted display name or group title can store markup that executes in the browser of anyone who views the notifications pane.

Taxonomy File Tree - Moderately Critical - Cross Site Request Forgery

Date
Severity
Moderately Critical
Affected versions
<7.x-1.2
The Taxonomy File Tree module exposes menu callbacks that restore an archived folder or file, moving taxonomy terms and re-saving nodes, but it performs these changes on a plain GET request with no anti-CSRF token, so an attacker can cause a privileged user to move or restore tree elements simply by getting them to load a crafted URL.

Open Atrium Notifications - Moderately Critical - Access Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-2.36
The Open Atrium Notifications remove callback deletes a notification subscription in response to a GET request but never validates the security token that its own remove links attach. An attacker can forge a request that makes an authenticated victim remove notification subscriptions without their consent.

Taxonomy File Tree - Critical - Cross Site Scripting

Date
Severity
Critical
Affected versions
<7.x-1.2
The Taxonomy File Tree module prints taxonomy term and folder names verbatim into HTML links and headings across its file explorer block, folder tree, and AJAX content table, allowing a low privilege group member who can create or rename a folder to store cross site scripting that executes in the browser of every user who later views the tree.

Taxonomy File Tree - Critical - Cross Site Scripting

Date
Severity
Critical
Affected versions
<7.x-1.2
The Taxonomy File Tree module builds the cancel link on its folder deletion form by inserting the raw destination query parameter into an anchor tag, allowing an attacker to craft a URL that injects arbitrary HTML into the page (reflected cross site scripting) or that points the cancel link at an external site (open redirect) for any user who opens the crafted link.

Open Atrium Notifications - Moderately Critical - Cross Site Request Forgery

Date
Severity
Moderately Critical
Affected versions
<7.x-2.36
The Open Atrium Notifications remove callback deletes a notification subscription in response to a GET request but never validates the security token that its own remove links attach. An attacker can forge a request that makes an authenticated victim remove notification subscriptions without their consent.

Get Directions - Moderately Critical - Cross Site Scripting

Date
Severity
Moderately Critical
Affected versions
<7.x-3.4
The Get Directions module places an unvalidated location string taken from a directions URL argument directly into the rendered directions form, allowing an attacker to craft a link that runs arbitrary JavaScript in the browser of any user who holds the getdirections access permission and follows it.

Popup - Moderately Critical - Access Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-1.5
The Popup module exposes an anonymous AHAH callback that renders the body of the targeted content without re-checking the current user's access, allowing an anonymous visitor to retrieve content they should not be able to see, such as an unpublished node.