- Advisory ID: DRUPAL-SA-CONTRIB-2010-011
- Project: Feedback (third-party module)
- Version: 5.x, 6.x
- Date: 2010-January-27
- Security risk: Moderately critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
Description
Feedback module enables users and visitors of a Drupal site to quickly send feedback messages about the currently displayed page. When displaying reports about submitted feedback, the module does not properly sanitize the user agent strings from the Browscap module before display, leading to a cross-site scripting (XSS) vulnerability. Such an attack may lead to a malicious user gaining full administrative access. Mitigating factors: this only impacts sites which also use the Browscap module and have the "Monitor browsers" feature enabled.
Versions affected
- Feedback for Drupal 6.x prior to 6.x-2.1
- Feedback for Drupal 5.x prior to 5.x-2.1
Drupal core is not affected. If you do not use the contributed Feedback module, there is nothing you need to do.
Solution
Upgrade to the latest version:
- If you use Feedback for Drupal 6.x upgrade to Feedback 6.x-2.1
- If you use Feedback for Drupal 5.x upgrade to Feedback 5.x-2.1
See also the Feedback project page.
Reported by
Fixed by
- Daniel Kudwien, the module maintainer
- Dave Reid
Contact
The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.