Date
Severity
Moderately Critical
Vulnerability
Cross Site Scripting
Affected versions
<7.x-3.4

Description

The Get Directions module provides Google Maps based directions between addresses and exposes a set of menu routes that build a directions form from arguments passed in the URL.

The module places a location string taken directly from the trailing URL argument of one of these routes into the markup of the directions form without sanitizing it, so any HTML or JavaScript contained in that argument is sent to the browser verbatim and executes when the page is viewed.

This vulnerability is mitigated by the fact that the affected route requires the access gmap getdirections permission, so a victim must hold that permission and be enticed to follow a crafted link.

Solution

Install the latest version.

If you use the Get Directions module for Drupal 7, upgrade to Get Directions 7.x-3.4:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES