Date
Severity
Less Critical
Vulnerability
Cross Site Scripting
Affected versions
<7.x-2.2

Description

The Profile Module Manager module shows a confirmation page before enabling a bundle that forces a logout, and on that page it lists the users who are currently active.

The module concatenates each username straight into the page HTML without passing it through an output sanitisation function, so any markup stored in a username is rendered as live HTML rather than as text.

This vulnerability is mitigated by the fact that Drupal core rejects usernames containing HTML metacharacters during normal registration and editing, so a payload username can only be present when it was created through a path that bypasses that validation, such as programmatic account creation, a migration, or an external authentication provider.

Solution

Install the latest version.

If you use the Profile Module Manager module for Drupal 7, upgrade to Profile Module Manager 7.x-2.2:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES