This module enables you to use the comScore Direct analytics system on a site.
The module doesn't sufficiently sanitize one of the configuration variables prior to rendering it.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer comScore direct".
Install the latest version:
- If you use the comScore Direct module for Drupal 7.x, upgrade to comScore Direct 7.x-1.3
- If you use the comScore Direct module for Drupal 6.x, upgrade to comScore Direct 6.x-1.2
- Tatár Balázs János
- Marcelo Vani the module maintainer
- Damien McKenna of the Drupal Security Team