Description
The Services module provides RESTful web services for Drupal, enabling file and content creation over HTTP.
The module validates uploaded files by extension only, so a file carrying an image extension such as .png but containing HTML or JavaScript passes validation and is stored to the public files directory, where it can later be referenced by an image field on a node.
This vulnerability is mitigated by the fact that the REST API file creation endpoints require an authenticated user with file creation permissions and that Drupal core serves stored files with a content type derived from the extension and the X Content Type Options nosniff header, which instructs browsers not to execute the payload as active content.
Solution
Install the latest version.
If you use the Services module for Drupal 7, upgrade to Services 7.x-3.30:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES