Search API Sorts - Moderately Critical - Cross Site Scripting (XSS)

* Advisory ID: DRUPAL-SA-CONTRIB-2017-015
* Project: Search API sorts (third-party module)
* Version: 7.x
* Date: 2017-February-15
* Security risk: 12/25 ( Moderately Critical)
* Vulnerability: Cross Site Scripting


The Search API Sorts module allows the site administrator to configure custom
sort options for their search results and expose the control interface via
the core block system.

The module doesn't sufficiently sanitize the name of the sort option which is
displayed to users.

This vulnerability is mitigated by the fact that an attacker must have a role
with permission 'administer search_api'.


* Search API Sorts 7.x-1.x versions prior to 7.x-1.7

Drupal core is not affected. If you do not use the contributed Search API
sorts module, there is nothing you need to do.


Install the latest version:

* If you use the Search API Sorts module for Drupal 7.x, upgrade to Search
API Sorts 7.x-1.7

Also see the Search API sorts project page.

Add new comment