September 2017

Global WordPress Translation Day

September 30 2017: a 24-hour, round-the-clock, digital and physical global marathon dedicated to the localisation of the WordPress platform and ecosystem, a structure that powers, today, over 28% of all existing websites.

September 1, 2017 – Global WordPress Translation Day 3 is a 24-hours live event organised by the WordPress Polyglots Team, whose mission is to translate WordPress into as many languages as possible which will run from 00.00 UTC until 23.59 UTC on September 30, 2017.

Page Access - Unsupported - SA-CONTRIB-2017-75

* Advisory ID: DRUPAL-SA-CONTRIB-2017-75
* Project: Page Access (third-party module)
* Date: 20-September-2017

DESCRIPTION

This module will provide the option to give the View and Edit access for
users and roles on each node pages.

The security team is marking this module unsupported. There is a known
security issue with the module that has not been fixed by the maintainer. If
you would like to maintain this module, please read:
https://www.drupal.org/node/251466

Skype Status - Moderately Critical - Cross Site Scripting - DRUPAL-SA-CONTRIB-2017-076

* Advisory ID: DRUPAL-SA-CONTRIB-2017-076
* Project: Skype Status
* Version: 7.x
* Date: 2017-September-20
* Security risk: 14/25 ( Moderately Critical)
* Vulnerability: Cross Site Scripting

DESCRIPTION

This module enables you to obtain the status for a user's Skype account

The module doesn't sufficiently sanitize the user input for their Skype ID.

This vulnerability is mitigated by the fact that an attacker must have an
account on the site and be allowed to edit/input their Skype ID.

VERSIONS AFFECTED

Flag clear - Moderately Critical - CSRF - DRUPAL-SA-CONTRIB-2017-074

* Advisory ID: DRUPAL-SA-CONTRIB-2017-074
* Project: Flag clear
* Version: 7.x
* Date: 2017-September-13
* Security risk: 14/25 ( Moderately Critical)
* Vulnerability: Cross Site Request Forgery

DESCRIPTION

The Flag clear module allows administrators to remove user flags for content.
This functionality is often useful in user-submission use-cases, where users
do not necessarily need to unflag things on their own.

The module doesn't sufficiently confirm a user's intent to take unflagging
actions.

CAPTCHA - Moderately Critical - Denial of Service - SA-CONTRIB-2017-073

* Advisory ID: DRUPAL-SA-CONTRIB-2017-073
* Project: CAPTCHA (third-party module)
* Version: 7.x
* Date: 2017-September-06
* Security risk: 10/25 ( Moderately Critical)
* Vulnerability: Denial of Service

DESCRIPTION

This module enables you to use various techniques to block automated scripts
/ robots from submitting content to a site, e.g. to block spam comments.

The module doesn't properly store the session ID of visitors who are given a
session which could lead to a Denial of Service attack.

Clientside Validation - Critical - Arbitrary PHP Execution - DRUPAL-SA-CONTRIB-2017-072

* Advisory ID: DRUPAL-SA-CONTRIB-2017-072
* Project: Clientside Validation (third-party module)
* Version: 7.x
* Date: 2017-September-06
* Security risk: 16/25 ( Critical)
* Vulnerability: Arbitrary PHP code execution

DESCRIPTION

The Clientside Validation module enables you to have clientside (Javascript)
validation on your forms.

The module does not sufficiently validate parameters of a POST request made
when validating a CAPTCHA.