===================================================================== CERT-Renater Note d'Information No. 2014/VULN154 _____________________________________________________________________ DATE : 07/08/2014 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Date for DRUPAL versions prior to 7.x-2.8. ====================================================================== https://www.drupal.org/node/2312609 ______________________________________________________________________ SA-CONTRIB-2014-073- Date - Cross Site Scripting (XSS) Posted by Drupal Security Team on July 30, 2014 at 3:25pm Advisory ID: DRUPAL-SA-CONTRIB-2014-073 Project: Date (third-party module) Version: 7.x Date: 2014-July-30 Security risk: Moderately Critical Vulnerability: Cross Site Scripting Description Date module provides flexible date/time field type Date field and a Date API that other modules can use. The module incorrectly prints date field titles without proper sanitization thereby opening a Cross Site Scripting (XSS) vulnerability. The vulnerability is mitigated by the fact that an attacker must have a permission to create Date fields, such as "administer taxonomy" to add date fields on taxonomy terms. CVE identifier(s) issued CVE-2014-5169 Versions affected Drupal core is not affected. If you do not use the contributed Date module, there is nothing you need to do. Solution Install the latest version: If you use the date module for Drupal 7.x, upgrade to Date 7.x-2.8 Also see the Date project page. Reported by Lucas D Hedding Fixed by Vijayachandran Mani the module maintainer Coordinated by Klaus Purer of the Drupal Security Team Contact and More Information The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact. Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site. ⋅ Categories: Drupal 7.x ========================================================= Serveur de référence du CERT-Renater https://services.renater.fr/ssi/ ========================================================== + CERT-RENATER | tel : 01-53-94-20-44 + + 23 - 25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email: cert@support.renater.fr + ==========================================================