Description
The Image Editor module provides integration with external online image editing services and includes editor plugins for Snipshot and FotoFlexer that return the browser to a Drupal callback endpoint after an image is edited.
The save callbacks for these two editors read an image value from the request query string and place it directly into an inline JavaScript string that is written to the page without any encoding, so an attacker who convinces a victim to follow a crafted link can escape the string literal and execute arbitrary JavaScript in the victim's browser.
This vulnerability is mitigated by the fact that exploiting it requires the victim to hold the use imageeditor permission and to follow a link prepared by the attacker.
Solution
Install the latest version.
If you use the Image Editor module for Drupal 7, upgrade to Image Editor 7.x-1.14:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES