Facets - Critical - Cross Site Scripting - SA-CONTRIB-2024-047
View online: https://www.drupal.org/sa-contrib-2024-047 Project: Facets [1] Date: 2024-October-09 Security risk: *Critical* 15 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:Default [2] Vulnerability: Cross Site Scripting Affected versions: <2.0.9 Description: This module enables you to to easily create and manage faceted search interfaces. The module doesn't sufficiently filter for malicious script leading to a reflected cross site scripting (XSS) vulnerability. Solution: Install the latest version: * If you use the Facets module, upgrade to Facets 2.0.9 [3] Reported By: * Andrea Racco [4] Fixed By: * Andrea Racco [5] * Markus Kalkbrenner [6] * Joris Vercammen [7] * Jimmy Henderickx [8] Coordinated By: * Greg Knaddison [9] of the Drupal Security Team * Juraj Nemec [10] of the Drupal Security Team [1] https://www.drupal.org/project/facets [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/facets/releases/2.0.9 [4] https://www.drupal.org/user/2950843 [5] https://www.drupal.org/user/2950843 [6] https://www.drupal.org/user/124705 [7] https://www.drupal.org/user/2393360 [8] https://www.drupal.org/user/462700 [9] https://www.drupal.org/u/greggles [10] https://www.drupal.org/u/poker10
participants (1)
-
security-news@drupal.org