it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116
- Date: Wed, 26 Aug 2026 18:34:15 +0000
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/SN5NOYKFWLZUNZ5TWCKL6YBMCYRVZBMC/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=YKKDJYC0; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=rYwwNTxL; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=xrQG+xDq; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-116
Project: Monster Menus [1]
Date: 2026-August-26
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Cross-site Scripting
Affected versions: <9.5.3
CVE IDs: CVE-2026-81201
Description:
This module enables you to create one or more multisites with highly granular
page permissions.
The module doesn't sufficiently sanitize HTML code contained in the page name
when displayed in the built-in tree browser. This results in a cross-site
scripting vulnerability that may allow attackers to execute arbitrary
JavaScript in the context of the user’s session.
This vulnerability is mitigated by the fact that an attacker must have the
ability to create pages whose page title supports HTML.
Solution:
Install the latest version:
* If you use the Monster Menus module, upgrade to monster_menus 9.5.3 [3].
Reported By:
* Dan Wilga (gribnif) [4]
Fixed By:
* Dan Wilga (gribnif) [5]
Coordinated By:
* Greg Knaddison (greggles) [6] of the Drupal Security Team
* Juraj Nemec (poker10) [7] of the Drupal Security Team
* Jess (xjm) [8] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [9]
[1] https://www.drupal.org/project/monster_menus
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/monster_menus/releases/9.5.3
[4] https://www.drupal.org/u/gribnif
[5] https://www.drupal.org/u/gribnif
[6] https://www.drupal.org/u/greggles
[7] https://www.drupal.org/u/poker10
[8] https://www.drupal.org/u/xjm
[9] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3589913
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116, security-news, 26.08.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.