it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-025 - TinyMCE - Cross Site Scripting (XSS)
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-025 - TinyMCE - Cross Site Scripting (XSS)
- Date: Wed, 10 Mar 2010 16:38:22 +0000 (UTC)
- List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
- List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>
* Advisory ID: DRUPAL-SA-CONTRIB-2010-025
* Project: TinyMCE (third-party module)
* Version: 5.x
* Date: 2010-March-09
* Security risk: Less Critical
* Exploitable from: Remote
* Vulnerability: Cross Site Scripting
.... Description
The TinyMCE module provides a "WYSIWYG" tool for entering rich text into
various parts of a site. The TinyMCE module displayed text entered by an
admin without filtering that text leading to a Cross Site Scription (XSS)
vulnerability. XSS vulnerabilities may expose site administrative accounts
which could lead to a variety of additional compromises. This vulnerability
is mitigated by the fact that an attacker must have the "administer tinymce"
permission which should generally only be granted to trusted roles.
.... Versions affected
* TinyMCE prior to 5.x-1.10.
Drupal core is not affected. If you do not use the contributed TinyMCE module
for Drupal 5, there is nothing you need to do.
.... Solution
Install the latest version:
* If you use TinyMCE for Drupal 5.x upgrade to TinyMCE 5.x-1.11 [1]
.... Reported by
* Justin C. Klein Keane [2]
.... Fixed by
* Kevin Reynen [3], the module maintainer
.... Contact
The security contact for Drupal can be reached at security at drupal.org or
via the form at http://drupal.org/contact.
[1] http://drupal.org/node/737176
[2] http://drupal.org/user/302225
[3] http://drupal.org/user/48877
_______________________________________________
Security-news mailing list
Security-news AT drupal.org
http://lists.drupal.org/mailman/listinfo/security-news
- [IT-SecurityNotifies] [Security-news] SA-CONTRIB-2010-025 - TinyMCE - Cross Site Scripting (XSS), security-news, 10.03.2010
Archiv bereitgestellt durch MHonArc 2.6.19.