Description

The Node Reference URL Widget module adds a new widget to the Node Reference field type, allowing node reference fields to be auto-populated based on a value from the URL.

The module does not sanitize some of the user-supplied data before displaying it, leading to a Cross Site Scripting (XSS) vulnerability that may lead to a malicious user gaining full administrative access.

Versions affected

  • Node Reference URL Widget module for Drupal 6 prior to 6.x-1.10.
  • Node Reference URL Widget module for Drupal 7 prior to 7.x-1.10.

Drupal core is not affected. If you do not use the contributed Node Reference URL Widget module, there is nothing you need to do.

Solution

Install the latest version:

See also the Node Reference URL Widget project page.

Reported by

Fixed by

Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.
Learn more about the team and their policies, writing secure code for Drupal, and secure configuration of your site.