Voting starts in March for the Drupal Association Board election.
- Advisory ID: SA-CONTRIB-2010-076
- Project: Dashboard (third-party module)
- Version: 6.x
- Date: 2010-July-28
- Security risk: Moderately critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
The dashboard module allows users to create a personalized set of pages of widgets created from existing blocks and nodes (like iGoogle).
The module does not escape user generated names for tags & titles associated with default widgets that are added to a user dashboard page, leading to a Cross Site Scripting (XSS) vulnerability. Users with the permission to access or create default dashboard widgets is vulnerable to attack. A malicious user needs the permission "administer dashboard defaults" to exploit the vulnerability.
- Dashboard module for Drupal 6.x versions prior to 6.x-2.1
Drupal core is not affected. If you do not use the contributed Dashboard module, there is nothing you need to do.
Install the latest version:
- Upgrade to Dashboard 6.x-2.1
See also the Dashboard project page.
- Greg Knaddison (greggles) a member of the Drupal Security Team