Date
Severity
Critical
Vulnerability
Path Traversal
Affected versions
<7.x-1.14

Description

The Image Editor module integrates external online editing services such as PicMonkey, Pixlr Editor, and Pixlr Express, which redirect the browser back to a Drupal save callback that fetches the edited image and stores it in the module temporary directory.

The save callbacks build the destination path by concatenating values taken directly from the request. The Pixlr callbacks assemble the path from the `title` and `type` GET parameters, while the PicMonkey callback takes the whole filename from the `imageeditor_filename` cookie. Because these values are never sanitized, an attacker can insert parent directory sequences into the name to place the file outside the intended temporary directory, and can choose any extension so the file is written with a dangerous type such as php inside the public files area, where it may be executed by the web server.

This vulnerability is mitigated by the fact that exploitation requires an authenticated account holding the "use imageeditor" permission and a valid external image URL that passes the module external URL validation.

Solution

Install the latest version.

If you use the Image Editor module for Drupal 7, upgrade to Image Editor 7.x-1.14:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES