Date
Severity
Moderately Critical
Vulnerability
Cross Site Scripting
Affected versions
≤7.x-2.3

Description

This is a port of a patched vulnerability by D7Security group in Coffee - Moderately critical - Cross Site Scripting - SA-CONTRIB-2024-011.

The module doesn't sufficiently escape menu names when displaying them in the popup, thereby exposing a XSS vulnerability. This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer menus and menu links".

This is a public release of the port of that patch, provided to Tag1 D7ES customers.

Solution

If you use the Coffee module, update to Coffee 7.x-2.4.


Reported by

  • Patrick Fey

Fixed by

  • Michael Mol
  • Klaus Purer
  • Oliver Köhler

Coordinated by

  • Tag1 D7ES