Description
The Popup module provides configurable popup elements, including a popup formats manager in the popup_ui submodule and configurable description popups in the popup_descriptions submodule.
The module exposes state changing operations as plain GET menu callbacks that are guarded only by the administer popup elements permission and carry no token, so a forged cross-site request issued by a logged in administrator's browser can delete, whipe, or reset popup formats and rewrite the description popup configuration variables without the administrator's intent.
This vulnerability is mitigated by the fact that exploitation requires the victim to be authenticated with the administer popup elements permission and to visit an attacker controlled page while logged in, and by the fact that the impact is limited to popup configuration changes.
Solution
Install the latest version.
If you use the Popup module for Drupal 7, upgrade to Popup 7.x-1.5:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES