Cross-Site Scripting Vulnerabilities in Project Issue File Review Module by Drupal
CVE-2014-8765

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
14 October 2014

Summary

The Project Issue File Review (PIFR) module for Drupal contains multiple cross-site scripting (XSS) vulnerabilities. These flaws allow remote attackers to inject arbitrary web scripts or HTML through carefully crafted patches. This occurs when a PIFR client tests a malicious patch, which then reflects results on the PIFR_Server's test results page. Additionally, authenticated users with 'manage PIFR environments' permissions can exploit these vulnerabilities through administrative pages. Such weaknesses can lead to severe security risks, including data theft and unauthorized actions within affected environments.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.