Date
Severity
Moderately Critical
Vulnerability
Cross-Site Request Forgery
Affected versions
<7.x-1.14

Description

The Image Editor module lets privileged users edit site images through external online editing services, exposing AJAX endpoints that upload a local file to an external image service and that overwrite a stored site image with fetched content.

The module doesn't validate a per session token on these two callbacks, protecting them only with a permission check while accepting requests that carry no token. Because the requests are predictable and require no secret value, a page under an attacker's control can silently submit a forged request that runs in the victim's authenticated session, causing a file to be uploaded to the external service or a site image to be overwritten.

This vulnerability is mitigated by the fact that exploitation requires a victim who is already logged in, who holds the relevant image editing permission, and who is induced to load a page controlled by the attacker.

Solution

Install the latest version.

If you use the Image Editor module for Drupal 7, upgrade to Image Editor 7.x-1.14:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES