Description
The Notify module sends email digests to subscribers when new content or comments are published, and provides admin forms for managing skip queues and user subscriptions.
The module's skip-queue admin form rendered user-controlled node titles and comment subjects, and its users admin form rendered subscriber email addresses, using the markup render element, which does not HTML-encode the output. A user with permission to create nodes or comments can craft a title or subject containing a script payload; when an administrator opens the notify skip queue, the script executes in the admin's browser session.
This vulnerability is mitigated by the requirement that an attacker have an authenticated account with content creation or comment posting permissions, and that an administrator visit one of the affected admin pages while the malicious content is present in the notify queue.
Solution
Install the latest version.
If you use the Notify module for Drupal 7, upgrade to Notify 7.x-1.9:
Reported by
Fixed by
Coordinated by
- Tag1 D7ES