Date
Severity
Moderately Critical
Vulnerability
Cross Site Scripting
Affected versions
<7.x-2.36

Description

The Open Atrium Notifications module provides notification subscriptions for Open Atrium content, letting users, groups, and teams be notified about activity within a space.

The module prints user supplied real names and group or team titles directly into a title HTML attribute in its notifications view template without sanitizing them.

This vulnerability is mitigated by the fact that an attacker needs an account that can set a display name or create a group or team, and the payload only fires when another user views the notifications detail pane.

Solution

Install the latest version.

If you use the Open Atrium Notifications module for Drupal 7, upgrade to Open Atrium Notifications 7.x-2.36:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES