Voting starts in March for the Drupal Association Board election.
- Advisory ID: DRUPAL-SA-CONTRIB-2009-075
- Project: Organic Groups Vocabulary (third-party module)
- Version: 5.x
- Date: 2009-October-21
- Security risk: Critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
The Organic Groups Vocabulary module enables an organic group to have a group specific vocabulary. In some specific cases, the module does not sanitize before outputting the group title, resulting in a cross-site scripting (XSS) vulnerability. Such an attack may lead to a malicious user gaining full administrative access.
- Organic Groups Vocabulary versions for Drupal 5.x before Organic Groups Vocabulary 5.x-1.1
Drupal core is not affected. If you do not use the contributed Organic Groups Vocabulary module, there is nothing you need to do.
Upgrade to the latest version:
- If you use Organic Groups Vocabulary for Drupal 5.x upgrade to version 5.x-1.1
See also the Organic Groups Vocabulary module project page.
Stéphane Corlosquet of the Drupal Security Team.
Amitaibu, the module maintainer.
The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.