The AltaGrade Blog

scroll to top - Moderately critical - Cross site scripting - SA-CONTRIB-2019-061

scroll to top - Moderately critical - Cross site scripting - SA-CONTRIB-2019-061

Project: scroll to top
Date: 2019-August-14
Security risk: Moderately critical 13∕25
Vulnerability: Cross site scripting

Description

The Scroll To Top module enables you to have an animated scroll to top link in the bottom of the node.

The module does not sufficiently filter configuration text leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer scroll to top".

Read More

Forms Steps - Critical - Access bypass - SA-CONTRIB-2019-064

Forms Steps - Critical - Access bypass - SA-CONTRIB-2019-064

Project: Forms Steps
Date: 2019-August-14
Security risk:  Critical 16∕25 
Vulnerability: Access bypass

Description

Forms Steps provides an UI to create form workflows using form modes. It creates quick and configurable multisteps forms.

The module doesn't sufficiently check user permissions to access its workflows entities that allows to see any entities that have been created through the different steps of its multistep forms.

Read More

External Links Filter - Moderately critical - Open Redirect Vulnerability - SA-CONTRIB-2019-063

External Links Filter - Moderately critical - Open Redirect Vulnerability - SA-CONTRIB-2019-063

Project: External Links Filter
Date: 2019-August-14
Security risk: Moderately critical 10∕25 
Vulnerability: Open Redirect Vulnerability

Description

The External Link Filter module provides an input filter that replaces external links by a local link that redirects to the target URL.

The module did not have protection for the Redirect URL to go where content authors intended.

Solution

Install the latest version:

Read More

Time to update WordPress to 5.2.1

Time to update WordPress to 5.2.1

A short-cycle maintenance 5.2.1 release WordPress has been announced today. The next version 5.2.2 is expected to follow in approximately two weeks.

This maintenance release fixes 33 bugs, including improvements to the block editor, accessibility, internationalization, and the Site Health feature introduced in 5.2.

Read More

Pages