Date
Severity
Less Critical
Vulnerability
Local File Disclosure
Affected versions
<7.14

Description

The Image Editor module lets authenticated users edit images in the browser and upload the resulting file to an external image hosting service through an AJAX callback.

The upload callback accepted a file location from a user supplied POST value, resolved it to an absolute path, and handed it to cURL as an upload field value without confining that path to the site files directory. On PHP versions before 5.6 cURL treats a field value that begins with the at sign as an instruction to read the named local file and send its contents, so an attacker could point the callback at any file the web server could read, such as settings.php containing database credentials or the system password file, causing the server to read that file and transmit its contents to the configured external service.

The severity of this issue depends heavily on the PHP version. On PHP 5.6 and later the safe upload behaviour is enabled by default and the at sign prefix is treated as a literal string rather than a file reference, so no file contents are disclosed and the request merely produces a harmless outbound POST carrying the path text. The full local file disclosure is therefore reproducible only on the older PHP versions that Drupal 7 still permitted. Exploitation in all cases also requires an authenticated account holding the "use imageeditor" permission.

Solution

Install the latest version.

If you use the Image Editor module for Drupal 7, upgrade to Image Editor 7.x-1.14:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES