[Security-news] Facets - Critical - Cross Site Scripting - SA-CONTRIB-2024-047

security-news at drupal.org security-news at drupal.org
Wed Oct 9 16:48:37 UTC 2024


View online: https://www.drupal.org/sa-contrib-2024-047

Project: Facets [1]
Date: 2024-October-09
Security risk: *Critical* 15 ∕ 25
AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Cross Site Scripting

Affected versions: <2.0.9
Description: 
This module enables you to to easily create and manage faceted search
interfaces.

The module doesn't sufficiently filter for malicious script leading to a
reflected cross site scripting (XSS) vulnerability.

Solution: 
Install the latest version:

   * If you use the Facets module, upgrade to Facets 2.0.9 [3]

Reported By: 
   * Andrea Racco [4]

Fixed By: 
   * Andrea Racco [5]
   * Markus Kalkbrenner [6]
   * Joris Vercammen [7]
   * Jimmy Henderickx [8]

Coordinated By: 
   * Greg Knaddison [9] of the Drupal Security Team
   * Juraj Nemec [10] of the Drupal Security Team


[1] https://www.drupal.org/project/facets
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/facets/releases/2.0.9
[4] https://www.drupal.org/user/2950843
[5] https://www.drupal.org/user/2950843
[6] https://www.drupal.org/user/124705
[7] https://www.drupal.org/user/2393360
[8] https://www.drupal.org/user/462700
[9] https://www.drupal.org/u/greggles
[10] https://www.drupal.org/u/poker10



More information about the Security-news mailing list