- Advisory ID: DRUPAL-SA-CONTRIB-2011-057
- Project: Support Ticketing System (third-party module)
- Version: 6.x
- Date: 2011-November-30
- Security risk: Moderately critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
Description
The Support Ticketing System module provides a basic ticketing system and helpdesk that is native to Drupal, offering complete email integration.
The module does not properly sanitize user-supplied content, resulting in multiple Cross-Site Scripting (XSS) vulnerabilities.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer support projects."
Versions affected
- support 6.x-1.x versions prior to 6.x-1.7.
Drupal core is not affected. If you do not use the contributed Support Ticketing System module, there is nothing you need to do.
Solution
Install the latest version:
- If you use the Support Ticketing System module for Drupal 6.x, upgrade to support 6.x-1.7
Note: If you were using the 6.x-1.6-rc1 release, or wish to test the latest 6.x version, you may upgrade to support 6.x-1.8-rc1.
See also the Support Ticketing System project page.
Reported by
Fixed by
- Brandon Bergren the module maintainer
Coordinated by
- Greg Knaddison of the Drupal Security Team
Contact and More Information
The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.
Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.