Description
The Feedback Collect module displays a feedback form that visitors can use to leave quick feedback, recording the page the feedback came from alongside the message.
The module does not sanitize the feedback origin value before returning it as markup, because its URL helper returns the stored value verbatim whenever that value is not a valid internal path, and the submitted feedback listing then places it into a table cell that is rendered without encoding. A user permitted to submit feedback, which for this module is commonly the anonymous role, can store a script payload in the origin field through the normal feedback submission request, and the payload executes when a privileged user opens the submitted feedback listing.
This vulnerability is mitigated by the requirement that a role be granted permission to view the submitted feedback for the payload to reach a privileged victim, and by the fact that the email column is separately constrained to valid email addresses.
Solution
Install the latest version.
If you use the Feedback Collect module for Drupal 7, upgrade to Feedback Collect 7.x-1.9:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES