Frequently Asked Questions - Moderately critical - Cross Site Scripting - SA-CONTRIB-2021-012
Project: Frequently Asked Questions
Date: 2021-June-02
Security risk: Moderately critical 11∕25
Vulnerability: Cross Site Scripting
Description
The Frequently Asked Questions (faq) module allows users, with appropriate permissions, to create question and answer pairs which they want displayed on the 'faq' page. The 'faq' page is automatically generated from the FAQ nodes configured. Basic Views layouts are also provided and can be customized via the Views UI (rather than via the module settings page).
The module doesn't sufficiently sanitize editor input leading to a Cross Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the "create faq content" permission.
Solution
Install the latest version:
- If you use the Frequently Asked Questions module for Drupal 7.x, upgrade to Frequently Asked Questions 7.x-1.3
We value your opinion. Please add your feedback.