it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-162
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-162
- Date: Wed, 23 Sep 2026 16:46:24 +0000
- Arc-authentication-results: i=2; smtp1.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=pHhC7+f5; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=BX5X+AV+; arc=none smtp.remote-ip=54.240.27.35
- Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 9961B841A3
- Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 9C9EA40282
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790185383; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=IeZfZrQvUPaBBbBAH8EyqRSxzUzNOTGZrh6Rl+zm0a0=; b=N8qH6izwShiVPxM5LjZatdhuVs6+Wbb8uBDy/0mIi1WjflULKBLFmkb2WypaN6hZgi6d 5LteUVjn8v2+odqk8tUMUByQ0n2EV79PGiMbGuOgavHGW1cayZ7T6/k7JjcTbk49Bx/sP YVdWMwyaE2jCDF3jw1rdASZMnBpEjOm4BNNetMRjCzmmfGXBLIdJtgQlPld9Y9Vrku9sO /oQvsw6W3jpEQm++dV2YQwurgtM/8xw1tg9K2zR8WyR4pNc7Jd8/wCV6851US2lyiT/7N ll4bTZF5E8/rI+CZMmtzMCzHefrhe9UHl06L9WfcjGZ9i17GgOOAQ879cJuLBjShePw==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790181984; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=1fTDAGTgbNgqhkaLF5DlA9kMWEcvU0f0PW6iR3xT5k8=; b=PSauP+Rtqgc21SonlqGli0rpz92ORvxCy7JtccqSg5t2BLqyG0z78uKjw20QyFT1bfTn cDm1fvY3hoTYzV0WJZphXrk1iVCDQZ4n38+aTMhdVw3ElhTcQSuA0R/EMYM53Qb15xuZP GDoj5YMnTD1Ne3mx8EpuOqeByBjsRWIf9Vk5BzOFK61hQMjEO4VspA8g7x3PtjqkvM8lw ni+2T+vGNyvQrovPw6cAgRL1sTuT/E91lTiv75sduLXLONICGzWArSNu8SWHvxX29YYLH ZT6xLlqrYvL++egyk6u0nFlvx/htcLotDGDRUpsqHHcMdlEYYCHvdmkLDWrwkpACTuQ==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790185383; b=EvfwbP1lV8LI0HBw5zmQN7fi6tYIrMj8zrnVbWxEO4l2l9PQn4UzqA2BTcPNnzB3bBYA 0KRhVh3Ml66h+ZfgjbOa0IX3c8bnaeQ1NjXdPgR0Q6DhnByif/bIhL6rPzCitN2MSAXPI 054w8VVGfDAvSQ7/0+AaViFeL1x8dzMkYd/7TmVTwVTNaurJBnUrmXtyGcYeASqc1P90M 7UMiCw1JvX/xeDffD1Y3gjF9ruloQVRKLB9bJc7+XW+wZRK18OjhFNGpAQKtIODOmizh7 /OHtvQ5qAkw8wUnLyAwGYIH+imogCiW2nAFUAMpydHAawvmQlD39/MpYhr+mpmisMQQ==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790181984; b=sjuDdU5X0Rooltif0rrZQEXrPUcP15WKKeRHGu51LGEda0ukwKrodoPFfLUqTCBWsU/Q e+Y2nAMmCOmYQ5u9zjIn3Tmdq8wdNmDzBXdzStSF+JtNJNO6Uor96Xh+T7iLA1EIEXwQ1 Shzn5GLSgJib3pH/r/drZZ+F4reUtySox5SE+3n7Xbmr/IZ1lC/Ew4PWWh8857ZThcY5Z PCvoIxvU6tZZVhvlMq77eu3sgIA40QLrSn/c5C4sRgYLa85UZeXyQX2WScwF4M2Gt+Cty G2wi52zF70JST9jNIa450Z9CsZZLV/ZWEF7//jQi8pyIu+2V2XlruklTiXRAJtobbvg==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/QFDQH3GNY7I5IMGIVYLRKJZ6OIWTCH3X/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=OoOdaOZH; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=pHhC7+f5; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=BX5X+AV+; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-162
Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:Uncommon [2]
Vulnerability: Cross-site scripting
Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96367
Description:
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data.
The module does not sufficiently restrict access to the custom attributes
YAML editor. Users with permission to create or edit webforms (but without
permission to edit webform source) may be able to add custom attributes,
leading to cross-site scripting.
This vulnerability is mitigated by the fact that an attacker must have a role
with permission to create or edit webforms.
Solution:
Install the latest version:
* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].
Reported By:
* Mitch Portier (arkener) [5]
Fixed By:
* Dan Chadwick (danchadwick) [6]
* Jacob Rockowitz (jrockowitz) [7]
* Liam Morland (liam morland) [8]
Coordinated By:
* Swan Kalata (akalata) [9] of the Drupal Security Team
* Bram Driesen (bramdriesen) [10] of the Drupal Security Team
* Damien McKenna (damienmckenna) [11] of the Drupal Security Team
* Juraj Nemec (poker10) [12] of the Drupal Security Team
* Pierre Rudloff (prudloff) [13] of the Drupal Security Team
* Jess (xjm) [14] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [15]
[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/arkener
[6] https://www.drupal.org/u/danchadwick
[7] https://www.drupal.org/u/jrockowitz
[8] https://www.drupal.org/u/liam-morland
[9] https://www.drupal.org/u/akalata
[10] https://www.drupal.org/u/bramdriesen
[11] https://www.drupal.org/u/damienmckenna
[12] https://www.drupal.org/u/poker10
[13] https://www.drupal.org/u/prudloff
[14] https://www.drupal.org/u/xjm
[15] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3611221
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-162, security-news, 23.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.