Closed (fixed)
Project:
DraggableViews
Version:
6.x-3.2
Component:
Code
Priority:
Critical
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
2 Dec 2009 at 19:16 UTC
Updated:
20 Jan 2010 at 15:00 UTC
Per http://drupal.org/node/475848, the security team has cleared this issue to be fixed publicly.
The draggableviews_repaired_msg is not sanitized before being passed to drupal_set_message, allowing an XSS attack. See line 331 of draggableviews.module
Comments
Comment #1
sevi commentedCommitted to Drupal-6--3 branch: http://drupal.org/cvs?commit=297026
Does this fixes this issue?
I'll add a new release soon.
Greetings,
sevi
Comment #2
sevi commented