- Advisory ID: DRUPAL-SA-CONTRIB-2012-036
- Projects: Content Lock, Ubercart Bulk Stock Updater, Ubercart Payflow Link, ticketyboo News Ticker, Admin tools, Redirecting click bouncer (third-party modules)
- Version: 6.x
- Version: 7.x
- Date: 2012-March-14
- Security risk: Critical
- Exploitable from: Remote
- Vulnerability: Information Disclosure
Content Lock Is a module that prevents users from concurrent editing of nodes. This module does not use a token for unlocking a content lock. This leads to a CSRF attack vector.
Ubercart Bulk Stock Updater is an extension module for Ubercart 2.x running on Drupal 6.x which makes it easy to bulk-edit product stock levels. This module does not properly use the formAPI and this results in a CSRF attack vector.
Ubercart Payflow Link is a payment solution for ubercart provided by PayPal. This module does not use a secure token and thus could allow payments to be forged.
ticketyboo News Tickeris a module that lets you configure three separate news tickers as Drupal Blocks. This module does not filter output correctly leading to a XSS attack vector. It may also have a SQL injection vector.
Admin tools XSS issue is
Admin tools CSRF issue is
Admin tools This package will contain a complete set of tools for managing several drupal installs. This module does not properly filter text leading to a XSS attack vector, as well as not checking tokens leading to a CSRF attack vector.
Redirecting click bouncer, is a module that lets you create links to a target that simply redirects to the real destination. The redirect happens server-side which means that we can track the redirects. This comes handy when we have links in our site and we need to know when they are clicked. This module does not check the URL to redirect to, this create an open redirect.
- All versions of Content Lock are affected by vulnerabilities.
- All versions of Ubercart Bulk Stock Updater payment are affected by vulnerabilities.
- All versions of Ubercart Payflow Link are affected by vulnerabilities.
- All versions of ticketyboo News Ticker are affected by vulnerabilities.
- All versions of Admin tools are affected by vulnerabilities.
- All versions of Redirecting click bouncer are affected by vulnerabilities.
Drupal core is not affected. If you do not use one of the contributed modules listed above, there is nothing you need to do.
Users of these modules are encouraged to disable the modules and search for similar alternatives. Users of the module who wish to take over maintainership should post patches to the issue queue to fix the security issues and request maintenance following the Unsupported project process.
- Content Lock issue reported by Charlie Gordon
- Ubercart Bulk Stock Updater issue reported by Peter Boden
- Ubercart Payflow Link issue reported by Dylan Tack of the Drupal Security Team
- ticketyboo News Ticker issue reported by Sascha Grossenbacher
- Admintools issue reported by Ivo Van Geertruyen of the Drupal Security Team
- Redirecting click bouncer issue reported by John T. Haller
No fixes created.
- Michael Hess of the Drupal Security Team
Contact and More Information
The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.
Edit: earlier versions of this SA mistakenly mentioned the print module.