Advanced Forum builds on and enhances Drupal's core forum module. When used in combination with other Drupal contributed modules, many of which are automatically used by Advanced Forum, you can achieve much of what stand alone software provides.
The module doesn't sufficiently sanitise user input in specific circumstances. It is not possible to disable the vulnerable functionality.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to create forum content.
Install the latest version:
- If you use the Advanced Forum module for Drupal 7.x, upgrade to Advanced Forum 7.x-2.8
Also see the Advanced Forum project page.
- Drew Webber of the Drupal Security Team
- Drew Webber of the Drupal Security Team
- Vijaya Chandran Mani Provisonal Member of the Drupal Security Team
- Drew Webber of the Drupal Security Team