• Advisory ID: DRUPAL-SA-CONTRIB-2010-011
  • Project: Feedback (third-party module)
  • Version: 5.x, 6.x
  • Date: 2010-January-27
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

Feedback module enables users and visitors of a Drupal site to quickly send feedback messages about the currently displayed page. When displaying reports about submitted feedback, the module does not properly sanitize the user agent strings from the Browscap module before display, leading to a cross-site scripting (XSS) vulnerability. Such an attack may lead to a malicious user gaining full administrative access. Mitigating factors: this only impacts sites which also use the Browscap module and have the "Monitor browsers" feature enabled.

Versions affected

  • Feedback for Drupal 6.x prior to 6.x-2.1
  • Feedback for Drupal 5.x prior to 5.x-2.1

Drupal core is not affected. If you do not use the contributed Feedback module, there is nothing you need to do.

Solution

Upgrade to the latest version:

See also the Feedback project page.

Reported by

Fixed by

Contact

The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.