PT-2014-5332 · Drupal · Flag
Murray Mcallister
·
Published
2014-05-17
·
Updated
2014-05-19
·
CVE-2014-3453
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Flag module versions 7.x-3.0 through 7.x-3.5
Description
The issue allows remote authenticated administrators to execute arbitrary PHP code via the "Flag import code" text area in the
/admin/structure/flags/import API endpoint. This could potentially be exploited by other attackers if the administrator ignores a security warning on the permissions assignment page.Recommendations
For Flag module versions 7.x-3.0 through 7.x-3.5, consider disabling the
flag import form validate function until a patch is available to prevent exploitation. Restrict access to the /admin/structure/flags/import endpoint to minimize the risk of arbitrary PHP code execution. Avoid using the Flag import code text area in the affected endpoint until the issue is resolved.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flag