Date
Severity
Critical
Vulnerability
Cross Site Scripting
Affected versions
<7.x-3.7

Description

The Calendar module provides a Views plugin for displaying date-based content as calendar views, including a stripe coloring feature that visually marks calendar items by taxonomy term or organic group.

The module outputs stripe labels (taxonomy term names and OG group names) directly into HTML title attributes in its stripe legend and stripe theme functions without sanitizing them, allowing HTML special characters to break out of the attribute context and inject executable script.

This vulnerability is mitigated by the fact that exploitation requires a user account with permission to create or edit taxonomy terms or manage organic groups, which is typically granted only to trusted editors or administrators.

Solution

Install the latest version.

If you use the Calendar module for Drupal 7, upgrade to Calendar 7.x-3.7:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES