Description
The Taxonomy File Tree module builds a file browser for Organic Groups and provides administrative forms to add, edit, delete, archive, and reorder the folders in that tree.
Several of those forms construct a cancel link whose target is taken directly from the destination request parameter and written into an anchor href with no escaping and no restriction to local paths, and the folder deletion form emits that link to the page, so a crafted link can break out of the attribute to run script in the victim browser or send the victim to an external address.
This vulnerability is mitigated by the fact that the victim must be a user who can reach the folder deletion form and must open a link prepared by the attacker.
Solution
Install the latest version.
If you use the Taxonomy File Tree module for Drupal 7, upgrade to Taxonomy File Tree 7.x-1.2:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES