Date
Severity
Critical
Vulnerability
Cross Site Scripting
Affected versions
<7.x-1.8

Description

The Mail Logger module records every outgoing mail that passes through the Drupal mail system and provides a page that shows a single logged mail together with a preview of its body.

When the stored body contains markup, the module writes that body into the document attribute of an inline frame rather than encoding it for display, and it places no restriction on that frame, so the browser parses the stored mail body as a document that inherits the origin of the site and runs any script it contains, including scripts that reach into the surrounding administrative page. The body of a mail sent through the default mail system is converted to plain text by a core function that decodes HTML entities, so an anonymous visitor who types an entity encoded payload into the core contact form has live markup stored in the log, and sites that send HTML mail store live markup in the ordinary course of operation.

This vulnerability is mitigated by the requirement that a role hold the permission to read the mail log for a payload to reach a victim, and by the requirement that the stored mail body contain markup rather than plain text only.

Solution

Install the latest version.

If you use the Mail Logger module for Drupal 7, upgrade to Mail Logger 7.x-1.8:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES