what you don't know can hurt you

Drupal Click2Sell Suite 6.x XSS / CSRF

Drupal Click2Sell Suite 6.x XSS / CSRF
Posted Sep 12, 2013
Authored by Greg Knaddison | Site drupal.org

Drupal Click2Sell Suite third party module version 6.x suffers from cross site request forgery and cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss, csrf
MD5 | 9680394ee071ae7e087e8001535f6e1a

Drupal Click2Sell Suite 6.x XSS / CSRF

Change Mirror Download
View online: https://drupal.org/node/2087055

* Advisory ID: DRUPAL-SA-CONTRIB-2013-075
* Project: Click2Sell Suite [1] (third-party module)
* Version: 6.x
* Date: 2013-September-11
* Security risk: Highly critical [2]
* Exploitable from: Remote
* Vulnerability: Cross Site Scripting, Cross Site Request Forgery

-------- DESCRIPTION
---------------------------------------------------------

Click2Sell is an Affiliate Marketing Network which lets you sell your
products through their marketplace or on your website with buy it now
buttons, and which also allows you to access hundreds of affiliates who want
to sell your product for you and earn commission.

.... Reflected Cross Site Scripting (XSS)

The module doesn't sufficiently filter user supplied data when presenting a
confirmation form.

.... Cross Site Request Forgery (CSRF)

The module doesn't properly use Drupal's Form API which allows a malicious
user to trick an admin into accidentally deleting information from
Click2Sell's database.


-------- CVE IDENTIFIER(S) ISSUED
--------------------------------------------

* /A CVE identifier [3] will be requested, and added upon issuance, in
accordance with Drupal Security Team processes./

-------- VERSIONS AFFECTED
---------------------------------------------------

* All Click2Sell Suite 6.x-1.x versions.

Drupal core is not affected. If you do not use the contributed Click2Sell
Suite [4] module, there is nothing you need to do.

-------- SOLUTION
------------------------------------------------------------

* If you use the Click2Sell Suite module for Drupal 6.x you should disable
it.

Also see the Click2Sell Suite [5] project page.

-------- REPORTED BY
---------------------------------------------------------

* Greg Knaddison [6] of the Drupal Security Team

-------- FIXED BY
------------------------------------------------------------

Not applicable.

-------- CONTACT AND MORE INFORMATION
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [7].

Learn more about the Drupal Security team and their policies [8], writing
secure code for Drupal [9], and securing your site [10].


[1] http://drupal.org/project/click2sell
[2] http://drupal.org/security-team/risk-levels
[3] http://cve.mitre.org/
[4] http://drupal.org/project/click2sell
[5] http://drupal.org/project/click2sell
[6] http://drupal.org/user/36762
[7] http://drupal.org/contact
[8] http://drupal.org/security-team
[9] http://drupal.org/writing-secure-code
[10] http://drupal.org/security/secure-configuration

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

February 2015

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    2 Files
  • 2
    Feb 2nd
    17 Files
  • 3
    Feb 3rd
    15 Files
  • 4
    Feb 4th
    16 Files
  • 5
    Feb 5th
    14 Files
  • 6
    Feb 6th
    4 Files
  • 7
    Feb 7th
    0 Files
  • 8
    Feb 8th
    0 Files
  • 9
    Feb 9th
    0 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2015 Packet Storm. All rights reserved.

close