Project
Date
Severity
Moderately Critical
Vulnerability
Cross Site Scripting
Affected versions
≤7.x-2.3
Description
This is a port of a patched vulnerability by D7Security group in Coffee - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-011.
The module doesn't sufficiently escape menu names when displaying them in the popup, thereby exposing a XSS vulnerability. This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer menus and menu links".
This is a public release of the port of that patch, provided to Tag1 D7ES customers.
Solution
If you use the Coffee module, update to Coffee 7.x-2.4.
Reported by
- Patrick Fey
Fixed by
- Michael Mol
- Klaus Purer
- Oliver Köhler
Coordinated by
- Tag1 D7ES