Description
The Image Editor module lets privileged users edit site images through external online editing services, exposing AJAX endpoints that upload a local file to an external image service and that overwrite a stored site image with fetched content.
The module doesn't validate a per session token on these two callbacks, protecting them only with a permission check while accepting requests that carry no token. Because the requests are predictable and require no secret value, a page under an attacker's control can silently submit a forged request that runs in the victim's authenticated session, causing a file to be uploaded to the external service or a site image to be overwritten.
This vulnerability is mitigated by the fact that exploitation requires a victim who is already logged in, who holds the relevant image editing permission, and who is induced to load a page controlled by the attacker.
Solution
Install the latest version.
If you use the Image Editor module for Drupal 7, upgrade to Image Editor 7.x-1.14:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES