• Advisory ID: DRUPAL-SA-CONTRIB-2011-024
  • Project: Spam (third-party module)
  • Version: 6.x
  • Date: 2011-June-08
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Request Forgery

Description

The Spam module provides numerous tools to auto-detect and deal with spam content that is posted to your site, without having to rely on third-party services.

The Spam module provides a trainable Bayesian filter, automatic learning of spammer URLs, flagging of content with an excessive number of links, the ability to create custom filters, and more.

The module does not properly protect "mark as spam" links against Cross-site Request Forgeries (CSRF), allowing a malicious user to trick an authorized user into marking content as spam. Wikipedia has more information about cross-site request forgery.

Versions affected

  • Spam module 6.x-1.x versions prior to 6.x-1.1

Drupal core is not affected. If you do not use the contributed Spam module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the spam module for Drupal 6.x upgrade to 6.x-1.1

See also the Spam project page.

Reported by

Fixed by

Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.