• Advisory ID: SA-CONTRIB-2010-076
  • Project: Dashboard (third-party module)
  • Version: 6.x
  • Date: 2010-July-28
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting


The dashboard module allows users to create a personalized set of pages of widgets created from existing blocks and nodes (like iGoogle).

The module does not escape user generated names for tags & titles associated with default widgets that are added to a user dashboard page, leading to a Cross Site Scripting (XSS) vulnerability. Users with the permission to access or create default dashboard widgets is vulnerable to attack. A malicious user needs the permission "administer dashboard defaults" to exploit the vulnerability.

Versions affected:

  • Dashboard module for Drupal 6.x versions prior to 6.x-2.1

Drupal core is not affected. If you do not use the contributed Dashboard module, there is nothing you need to do.


Install the latest version:

See also the Dashboard project page.

Reported by:

Fixed by:

The Drupal security team can be reached at security at drupal.org or via the form at http://drupal.org/contact.