Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161
  • Date: Wed, 23 Sep 2026 16:46:46 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=ADR6vMYw; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=ckJslbZL; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=ADR6vMYw; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=ckJslbZL; arc=none smtp.remote-ip=54.240.27.123
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 92D8142D43
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 1E8E940282
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790185691; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=GMksqbJdT1r0djwdVP3d+Lg4yUQLxQUlpEbr7eMuB2Q=; b=AZsWLvSr6oiNY1ON/8ir4BUvBSO7Vk+zOAa1QAtbDIxqBWruI3I6wqM4tG3L54kibije kCilg+PgdqVtv0pRCth1ZA7v+5FZzvsNNxYu3zTyvaMSYbRh1l43MZUDbxiolIsvmLW8w 4dFxKNklVCz3NSYFWvxilH7rs7pKQPdekUrsl0OrPua75puKkSvMgVKOWb/Kj9Ct4r9a7 EqXNn9jzPXddrCS3EZD6ZkMvHheV0Sm/T9evqnSZnsNnmjpB+mfRDRkIenZwgsdWtYuFB cPDbrNSPpv9W/rTjKuyK1PwUS2yUIaC5ZValC/noFPF67mnuxlaMK32QyGjOoF+NHcQ==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790182009; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=527yWbGmABbp0rlpNNLHO9k4WAt+nWmqaJGfKzqFkjE=; b=Ll7NVx9K6YqeaPcBJZRrfQx+fYYQqM2YC3M3Im7e60EFhi7/p9V+lXJHu05VfLIFK6vF 3vBSshEFWxEWyyyYeYde8y+/9wI2T1+GLn/Msv9wJYqKXk09v+SROplD2bNwsOZ1j3h6f hhvPMRRJA1z9kL3vsFNYDsUifOGBN+q+h9SrTg5IHmlRdEOkGaVMsWTr0K22RJs5DeoJU Ax7WxAeleRcC49eAwKbpnYY8sggwnO0s3TIf6rpsMvj8LzEt0PkZlZnfG/bijNdUeIOKy sRyHaZOx6uCOg22UMPLRXqURRuH2/QvVuKmA4EpqU29994PWvN+JFkUcmqrTiX6C3dw==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790185691; b=gyEwKX91aAwLRrsstRKZbBYTlKTWMJ+UEPuC9iem2NwSAbNNfNgcadPRw+ErDk7gsDHH uZdf4YyA/9w3GtpB9cKsz1oGM9iL5TvT2usDIS15bjOBjbfZUewDggSWoSVNF1sZ2Dds2 mCcHlunC7/g3FK/ehAB+Bnwy8dbxvRPunFxweFhb6nEgqFaC4NPHO91uP5SMwAFRYKmep Um9FunedembLvVAzRuYkmhfT1uConHv3+Amv+JY/XrRYzWKOnFFHH7Xyg8Ifkbj5GWUU2 ZXR0ber7WDKLYjdG20tPEFc3xCl3ZoMrsTSElghPsfcpnF73jA2HAcm1cFtKt624UdQ==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790182009; b=G/Om+6gY/ADIG4hir8l0tFrffnURKfHW25zP47nVg3QIMGd0ylgaq7ocdOF5jRQZcTyg nJDsLqvfya5XiV/M5vLHxUjbf2KLXx1r17/xLqz611CgYXtp7ZCmUYwHavQMPcSgDxdvB RxMIXTCgu3MTSRZSt6o4Cktp3vQluTT1awOv3LeJFOLt255MX6xhrnILBk3K1cjK9mfgB LW9tqNdTZ1P+5nBjy81uphwQpQgYfr36rdJwz0n1aVYXGUYeRQpZYp6yAB3wTTzSgVbnY UUpg89x52OmLLC6WHzXN0jdOzcD4AdM5R94dNQH+3vx48eayWzLfvVy8Lh3bJDUlzsw==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/7CY5IWCU6SHMD6N4GWTGAUVDLUS7Z4DD/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b="P+LKvA/N"; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=ADR6vMYw; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=ckJslbZL; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-161

Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 10 ∕ 25
AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2]
Vulnerability: Cross-site scripting

Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96363
Description: 
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data.

Webform includes a submodule called Webform Entity Print. This submodule
doesn't sufficiently limit access to its print templates. When the submodule
is enabled, a user with permissions to create a webform can exploit
cross-site scripting (XSS) in submodule settings.

This vulnerability is mitigated by the fact that an attacker must have a role
with /create webform/ and /edit own webform/ permissions, and the Webform
Entity Print module must be enabled.

Solution: 
Install the latest version:

* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].

Reported By: 
* Pierre Rudloff (prudloff) [5] of the Drupal Security Team

Fixed By: 
* Dan Chadwick (danchadwick) [6]
* Jacob Rockowitz (jrockowitz) [7]
* Liam Morland (liam morland) [8]

Coordinated By: 
* Swan Kalata (akalata) [9] of the Drupal Security Team
* Bram Driesen (bramdriesen) [10] of the Drupal Security Team
* cilefen (cilefen) [11] of the Drupal Security Team
* Greg Knaddison (greggles) [12] of the Drupal Security Team
* Ivo Van Geertruyen (mr.baileys) [13] of the Drupal Security Team
* Juraj Nemec (poker10) [14] of the Drupal Security Team
* Jess (xjm) [15] of the Drupal Security Team
* Cathy Theys (yesct) [16] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [17]

[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/prudloff
[6] https://www.drupal.org/u/danchadwick
[7] https://www.drupal.org/u/jrockowitz
[8] https://www.drupal.org/u/liam-morland
[9] https://www.drupal.org/u/akalata
[10] https://www.drupal.org/u/bramdriesen
[11] https://www.drupal.org/u/cilefen
[12] https://www.drupal.org/u/greggles
[13] https://www.drupal.org/u/mrbaileys
[14] https://www.drupal.org/u/poker10
[15] https://www.drupal.org/u/xjm
[16] https://www.drupal.org/u/yesct
[17] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3610996

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang