Cross-Site Scripting Vulnerabilities in Project Issue File Review Module by Drupal
CVE-2014-8765
Currently unrated
Summary
The Project Issue File Review (PIFR) module for Drupal contains multiple cross-site scripting (XSS) vulnerabilities. These flaws allow remote attackers to inject arbitrary web scripts or HTML through carefully crafted patches. This occurs when a PIFR client tests a malicious patch, which then reflects results on the PIFR_Server's test results page. Additionally, authenticated users with 'manage PIFR environments' permissions can exploit these vulnerabilities through administrative pages. Such weaknesses can lead to severe security risks, including data theft and unauthorized actions within affected environments.
References
Timeline
Vulnerability Reserved
Vulnerability published