- Leaving the ajax for scs_views behind
- Added possibility for default title
- Coding standards
- New theme functions
- Updated INSTALL.txt
- Theming for node output is now in front-end theme
- Bugfixes
SA-CONTRIB-2010-087 - GovDelivery - Cross site scripting
The GovDelivery module provides integration with the GovDelivery On-Demand Mailer service, a web service for GovDelivery customers that sends messages directly based on configured account information. The module replaces the backend of SMTP library in your Drupal site with calls to the GovDelivery service, so all mail sent from your site uses the ODM service.
The module does not sanitize some of the user-supplied data before displaying it (for Drupal 6.x-1.0 only), leading to a Cross Site Scripting (XSS).
The Prepopulate module provides the ability for form fields to be pre-populated via the request sent for the form.
The module is vulnerable to access bypass which would allow a malicious user to change the value of fields they would not otherwise have access to alter.
The Prepopulate module provides the ability for form fields to be pre-populated via the request sent for the form.
The module is vulnerable to access bypass which would allow a malicious user to change the value of fields they would not otherwise have access to alter.