Date
Severity
Moderately Critical
Vulnerability
Cross Site Scripting
Affected versions
<7.x-1.14

Description

The Bean module enables the creation of reusable block entities (Bean Blocks) that can be placed throughout a Drupal site.

The module does not sanitize the bean title before it reaches the bean template, which prints it directly inside a heading element on the standalone bean view page. The block rendering path correctly filters the same title against the documented list of allowed HTML tags, but the entity preprocess pipeline applies no equivalent sanitization for the standalone view path.

This vulnerability is mitigated by the fact that an attacker must hold the permission to create or edit beans of a given type, and a victim must have permission to view the bean page and must visit the standalone bean view page.

Solution

Install the latest version.

If you use the Bean module for Drupal 7, upgrade to Bean 7.x-1.14:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES