Description
The Content Menu module provides a content centric menu management interface for editors.
The module does not verify that the current user is permitted to administer menus before saving a menu link whose menu, parent, title, weight and visibility are all taken from user controlled query string parameters when a node is inserted. A user who can create any content type can therefore place a menu link into any menu, including system menus such as the main menu, without the menu administration permission that Drupal core normally requires for menu link management.
This vulnerability is mitigated by the fact that an attacker must have an authenticated account with at least one content creation permission, and the injected link target is limited to the newly created node path.
Solution
Install the latest version.
If you use the Content Menu module for Drupal 7, upgrade to Content Menu 7.x-1.1:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES