Drupal FAQ Module Script Insertion Vulnerability | Develop Site

dev1961's picture

SECUNIA ADVISORY ID:
SA37923

VERIFY ADVISORY:
http://secunia.com/advisories/37923/

DESCRIPTION:
Some vulnerabilities have been reported in the FAQ module for Drupal,
which can be exploited by malicious users to conduct script insertion
attacks.

Certain input passed via an unspecified parameter is not properly
sanitised before being displayed to the user. This can be exploited
to insert arbitrary HTML and script code, which will be executed in a
user's browser session in context of an affected site when the
malicious data is being viewed.

Successful exploitation requires 'administer faq', 'create faq', or
'edit faq' permissions.

The vulnerabilities are reported in versions prior to 6.x-1.11 or
5.x-2.14.

SOLUTION:
FAQ 6.x:
Update to version 6.x-1.11.
http://drupal.org/node/666776

FAQ 5.x:
Update to version 5.x-2.14.
http://drupal.org/node/666770

English
Tags [en:field:taxonomy_vocabulary_3:story:label]: