Drupal Association members fund grants that make connections all over the world.
- Advisory ID: DRUPAL-SA-CONTRIB-2013-076
- Project: jQuery Countdown (third-party module)
- Version: 7.x
- Date: 2013-September-11
- Security risk: Less critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
This jQuery Countdown Module enables you to display a countdown block based upon date settings.
The jQuery Countdown Module does not properly sanitize the settings, allowing a malicious user to embed scripts within a page, resulting in a Cross-site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have the "access administration pages" permission.
CVE identifier(s) issued
- jquery_countdown 7.x-1.x versions prior to 7.x-1.0.
Drupal core is not affected. If you do not use the contributed jQuery Countdown module, there is nothing you need to do.
Install the latest version:
- If you use the jQuery Countdown module, upgrade to jQuery Countdown 7.x-1.1
Also see the jQuery Countdown project page.
- Dennis Brücke the module maintainer
Contact and More Information
The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.