Description
The Brightcove Video Connect module provides a video upload form that lets a user supply poster and thumbnail images alongside the video before it is sent to Brightcove.
The form validates those images by file extension alone, so a file that carries an image extension but contains an HTML or JavaScript payload passes validation and is saved to the public files directory.
This vulnerability is mitigated by the fact that the upload form requires a privileged role and that Drupal core serves the stored file with an extension derived content type and an X Content Type Options nosniff header, which stops a browser from running the payload as active content.
Solution
Install the latest version.
If you use the Brightcove Video Connect module for Drupal 7, upgrade to Brightcove Video Connect 7.x-6.7:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES