drupal-webform
Page content
- Author: Miklos Vajna
- Vulnerable: 5.x_2.7-1
- Unaffected: 5.x_2.8-1getorin1
Some vulnerabilities have been reported in the Webform module for Drupal, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to disclose potentially sensitive information.
- Input passed to field labels while creating new webforms is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user’s browser session in context of an affected site when the malicious data is being viewed. Successful exploitation of this vulnerability requires permissions to create webforms.
- An error in the handling of cached pages can be exploited to disclose session variables when caching is enabled.
- Bug Tracker URL: http://bugs.frugalware.org/task/4000