SB2017011207 - Stored XSS in Autocomplete Deluxe module for Drupal



SB2017011207 - Stored XSS in Autocomplete Deluxe module for Drupal

Published: January 12, 2017

Security Bulletin ID SB2017011207
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Stored cross-site scripting (CVE-ID: N/A)

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability is caused by incorrect filtration of input data passed via taxonomy terms. A remote authenticated attacker with privileges to edit taxonomy field can permanently inject arbitrary HTML and script code, and execute it in victim’s browser in security context of vulnerable website, when the victim visits malicious page.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Remediation

Install update from vendor's website.