Scoutnet vzw
http://forum.scoutnet.be/

[Drupal] Security announcements: Workflow - XSS
http://forum.scoutnet.be/viewtopic.php?f=19&t=2057
Pagina 1 van 1

Auteur:  To [ 24 Jan 2008 20:35 ]
Titel:  [Drupal] Security announcements: Workflow - XSS

------------SA-2008-009 - WORKFLOW - CROSS SITE SCRIPTING------------

* Advisory ID: DRUPAL-SA-2008-009
* Project: Workflow (third-party module)
* Version: 4.7.x, 5.x
* Date: 2008-January-23
* Security risk: Not critical
* Exploitable from: Remote
* Vulnerability: Cross site scripting

------------DESCRIPTION------------

The Workflow module allows the creation and assignment of arbitrary workflows to Drupal node types.

Workflow does not escape certain node properties on output. It is therefore possible to inject arbitrary HTML and script code into certain workflow messages (such as those displayed on the workflow tab), which may lead to administrator access if certain conditions are met. Learn more about cross site scripting on Wikipedia [ http://en.wikipedia.org/wiki/Cross_site_scripting ].

------------VERSIONS AFFECTED------------

* Workflow for Drupal 4.7.x before Workflow 4.7.x-1.2
* Workflow for Drupal 5.x before Workflow 5.x-1.2

Drupal core is not affected. If you do not use the contributed Workflow module, there is nothing you need to do.

------------SOLUTION------------

Install the latest version:

* If you use Drupal 5.x upgrade to Workflow 4.7.x-1.2 [ http://drupal.org/node/211114 ].
* If you use Drupal 5.x upgrade to Workflow 5.x-1.2 [ http://drupal.org/node/210165 ].

See also the Workflow project page [ http://drupal.org/project/workflow ].

------------REPORTED BY------------

Greg Knaddison (greggles [ http://drupal.org/user/36762 ]).

------------CONTACT------------

The security contact for Drupal can be reached at security at drupal.org or via the form at [ http://drupal.org/contact ].

Pagina 1 van 1 Alle tijden zijn UTC + 1 uur
Powered by phpBB® Forum Software © phpBB Group
http://www.phpbb.com/