Description
The Image Editor module integrates external online editing services such as PicMonkey, Pixlr Editor, and Pixlr Express, which redirect the browser back to a Drupal save callback that fetches the edited image and stores it in the module temporary directory.
The save callbacks build the destination path by concatenating values taken directly from the request. The Pixlr callbacks assemble the path from the `title` and `type` GET parameters, while the PicMonkey callback takes the whole filename from the `imageeditor_filename` cookie. Because these values are never sanitized, an attacker can insert parent directory sequences into the name to place the file outside the intended temporary directory, and can choose any extension so the file is written with a dangerous type such as php inside the public files area, where it may be executed by the web server.
This vulnerability is mitigated by the fact that exploitation requires an authenticated account holding the "use imageeditor" permission and a valid external image URL that passes the module external URL validation.
Solution
Install the latest version.
If you use the Image Editor module for Drupal 7, upgrade to Image Editor 7.x-1.14:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES