[Security-news] SA-CONTRIB-2009-061 - Markdown Preview - Cross Site Scripting

security-news at drupal.org security-news at drupal.org
Wed Sep 23 16:18:35 UTC 2009


  * Advisory ID: DRUPAL-SA-CONTRIB-2009-061
  * Project: Markdown Preview (third-party module)
  * Version: 6.x
  * Date: 2009 September 23
  * Security risk: Less critical
  * Exploitable from: Remote
  * Vulnerability: Cross Site Scripting

-------- DESCRIPTION  
---------------------------------------------------------

The Markdown Preview module provides a live preview pane that displays the
rendered HTML output of your Markdown input. When displaying the live
preview, the module does not properly escape user entered data, leading to a
cross-site scripting (XSS [1]) vulnerability. Such an attack may lead to a
malicious user gaining full administrative access.
-------- VERSIONS AFFECTED  
---------------------------------------------------

  * Markdown Preview for Drupal 6.x

Drupal core is not affected. If you do not use the contributed Markdown
Preview module, there is nothing you need to do.
-------- SOLUTION  
------------------------------------------------------------

The Markdown Preview module has been abandoned and its releases have been
unpublished. It is recommended that it be disabled and removed from your
server if in use. For Markdown live preview functionality for nodes and
comments, use the Live module [2], which properly escapes the user entered
data using the content's current input format. See the Markdown Preview
project page [3] for instructions how to enable Markdown preview
functionality with the Live module [4].
-------- REPORTED BY  
---------------------------------------------------------

Reported by David Needham [5].
-------- HANDLED BY  
----------------------------------------------------------

On behalf of Drupal security team, this module has been handled by Stéphane
Corlosquet [6], Oleg Terenchuk [7], and Dave Reid [8].
-------- CONTACT  
-------------------------------------------------------------

The security contact for Drupal can be reached at security at drupal.org or
via the form at http://drupal.org/contact.

[1] http://en.wikipedia.org/wiki/Cross_Site_Scripting
[2] http://drupal.org/project/live
[3] http://drupal.org/project/markdownpreview
[4] http://drupal.org/project/live
[5] http://drupal.org/user/191261
[6] http://drupal.org/user/52142
[7] http://drupal.org/user/78134
[8] http://drupal.org/user/53892



More information about the Security-news mailing list