Description
The Calendar module provides a Views plugin for displaying date-based content as calendar views, including a stripe coloring feature that visually marks calendar items by taxonomy term or organic group.
The module outputs stripe labels (taxonomy term names and OG group names) directly into HTML title attributes in its stripe legend and stripe theme functions without sanitizing them, allowing HTML special characters to break out of the attribute context and inject executable script.
This vulnerability is mitigated by the fact that exploitation requires a user account with permission to create or edit taxonomy terms or manage organic groups, which is typically granted only to trusted editors or administrators.
Solution
Install the latest version.
If you use the Calendar module for Drupal 7, upgrade to Calendar 7.x-3.7:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES