This page displays all public Tag1 D7ES Security Advisories. Check out our Announcements page for all updates.

You can filter this list by project or subscribe to the RSS feed.

 

Open Atrium Notifications - Moderately Critical - Cross Site Request Forgery

Date
Severity
Moderately Critical
Affected versions
<7.x-2.36
The Open Atrium Notifications remove callback deletes a notification subscription in response to a GET request but never validates the security token that its own remove links attach. An attacker can forge a request that makes an authenticated victim remove notification subscriptions without their consent.

Taxonomy File Tree - Critical - Cross Site Scripting

Date
Severity
Critical
Affected versions
<7.x-1.2
The Taxonomy File Tree module builds the cancel link on its folder deletion form by inserting the raw destination query parameter into an anchor tag, allowing an attacker to craft a URL that injects arbitrary HTML into the page (reflected cross site scripting) or that points the cancel link at an external site (open redirect) for any user who opens the crafted link.

Open Atrium Notifications - Moderately Critical - Access Bypass

Date
Severity
Moderately Critical
Affected versions
<7.x-2.36
The Open Atrium Notifications remove callback deletes a notification subscription in response to a GET request but never validates the security token that its own remove links attach. An attacker can forge a request that makes an authenticated victim remove notification subscriptions without their consent.

Taxonomy File Tree - Moderately Critical - Cross Site Request Forgery

Date
Severity
Moderately Critical
Affected versions
<7.x-1.2
The Taxonomy File Tree module exposes menu callbacks that restore an archived folder or file, moving taxonomy terms and re-saving nodes, but it performs these changes on a plain GET request with no anti-CSRF token, so an attacker can cause a privileged user to move or restore tree elements simply by getting them to load a crafted URL.

Get Directions - Moderately Critical - Cross Site Scripting

Date
Severity
Moderately Critical
Affected versions
<7.x-3.4
The Get Directions module places an unvalidated location string taken from a directions URL argument directly into the rendered directions form, allowing an attacker to craft a link that runs arbitrary JavaScript in the browser of any user who holds the getdirections access permission and follows it.

Taxonomy File Tree - Critical - Cross Site Scripting

Date
Severity
Critical
Affected versions
<7.x-1.2
The Taxonomy File Tree module prints taxonomy term and folder names verbatim into HTML links and headings across its file explorer block, folder tree, and AJAX content table, allowing a low privilege group member who can create or rename a folder to store cross site scripting that executes in the browser of every user who later views the tree.

Open Atrium Notifications - Moderately Critical - Cross Site Scripting

Date
Severity
Moderately Critical
Affected versions
<7.x-2.36
The Open Atrium Notifications view template prints real names and group or team titles into an HTML title attribute without sanitization. A user who sets a crafted display name or group title can store markup that executes in the browser of anyone who views the notifications pane.

Popup - Moderately Critical - Cross Site Scripting

Date
Severity
Moderately Critical
Affected versions
7.x-1.5
The Popup Filter submodule builds HTML option elements from block information and view display titles without sanitization and returns them as an HTML response that the popup insert form injects into the page, allowing stored cross-site scripting against administrators who use the insert form.