HomeSecuritySecurity expert disappointed by XSS bug fix in Drupal 8

Security expert disappointed by XSS bug fix in Drupal 8

drupal 8Drupal 8 hasn't been released yet, but security experts have been busy patching the code and reporting bugs, helping the open source community strengthen one of its favorite Content Management Systems (CMSs).

Sandeep Kamble , a researcher for SecureLayer 7 , has discovered a cross - site scripting ( XSS ) vulnerability in the beta14 version of Drupal 8.0.0.

The vulnerability was found in the file “\core\vendor\behat\mink\driver-testsuite\web-fixtures\issue130.php”, which according to Kamble, contains a PHP super GLOBAL variable ($_SERVER['HTTP_REFERER']) that fails to properly validate the requested data.

This allows attackers to attempt an XSS attack and execute malicious code on the infected versions of Drupal 8.

The company was quick with the fixes, and because it was only in one of the beta versions, few users were actually affected by the vulnerability, given that this version is not recommended by the company for production environments.

Kamble's problem, however, was that the company fixed the bug using a non-recommended method, at least not the one recommended by Microsoft, or the OWASP (Open Web Application Security Project) through the XSS Prevention Cheat Sheet.

“They decided to use '.htaccess' as a patch, which is not a suitable mechanism to fix this XSS, no filters or encoders were used,” Kamble states and continues by recommending “various other mechanisms can be used for successful filtering & encoding such as Html Encode, HtmlAttributeEncode, JavaScriptEncode etc.”.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS