Description
The Profile Module Manager module shows a confirmation page before enabling a bundle that forces a logout, and on that page it lists the users who are currently active.
The module concatenates each username straight into the page HTML without passing it through an output sanitisation function, so any markup stored in a username is rendered as live HTML rather than as text.
This vulnerability is mitigated by the fact that Drupal core rejects usernames containing HTML metacharacters during normal registration and editing, so a payload username can only be present when it was created through a path that bypasses that validation, such as programmatic account creation, a migration, or an external authentication provider.
Solution
Install the latest version.
If you use the Profile Module Manager module for Drupal 7, upgrade to Profile Module Manager 7.x-2.2:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES