* Advisory ID: DRUPAL-SA-CONTRIB-2012-024 * Project: MediaFront [1] (third-party module) * Version: 6.x, 7.x * Date: 2012-February-29 * Security risk: Less Critical [2] * Exploitable from: Remote * Vulnerability: Cross Site Scripting
-------- DESCRIPTION ---------------------------------------------------------
Within the MediaFront module, there is a PHP library for handling the stand alone application of the Open Standard Media player. Within this library, both the $_SESSION and $_SERVER variables are handled without proper checks to make sure that no malicious code is injected within these variables.
-------- VERSIONS AFFECTED ---------------------------------------------------
* MediaFront 6.x-1.x versions prior to 6.x-1.5. * MediaFront 7.x-1.x versions prior to 7.x-1.5.
Drupal core is not affected. If you do not use the contributed MediaFront [3] module, there is nothing you need to do.
-------- SOLUTION ------------------------------------------------------------
Install the latest version:
* If you use the Mediafront module for Drupal 6.x, upgrade to Mediafront 6.x-1.5 [4] * If you use the Mediafront module for Drupal 7.x, upgrade to Mediafront 7.x-1.5 [5]
See also the MediaFront [6] project page.
-------- REPORTED BY ---------------------------------------------------------
* Óscar Estepa [7]
-------- FIXED BY ------------------------------------------------------------
* Travis Tidwell [8] the module maintainer
-------- COORDINATED BY ------------------------------------------------------
* Michael Hess [9] of the Drupal Security Team
-------- CONTACT AND MORE INFORMATION ----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact [10].
Learn more about the Drupal Security team and their policies [11], writing secure code for Drupal [12], and securing your site [13].
[1] http://drupal.org/project/mediafront [2] http://drupal.org/security-team/risk-levels [3] http://drupal.org/project/mediafront [4] https://drupal.org/node/1460892 [5] https://drupal.org/node/1460894 [6] http://drupal.org/project/mediafront [7] http://drupal.org/user/1306904 [8] http://drupal.org/user/98581 [9] http://drupal.org/user/102818 [10] http://drupal.org/contact [11] http://drupal.org/security-team [12] http://drupal.org/writing-secure-code [13] http://drupal.org/security/secure-configuration