• Advisory ID: DRUPAL-SA-CONTRIB-2009-020
  • Project: Printer, e-mail and PDF versions (third-party module)
  • Version: 5.x, 6.x
  • Date: 2009-April-15
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross-site scripting (XSS)

Description

The Printer, e-mail and PDF versions ("Print") module provides printer-friendly versions of content. The module does not correctly escape content titles, enabling malicious users to insert arbitrary HTML and scripts into certain pages. Such a cross site scripting (XSS) attack against sufficiently privileged users may lead to administrator access to the site.

Versions affected

  • Versions of Printer, e-mail and PDF versions for Drupal 5.x prior to 5.x-4.5
  • Versions of Printer, e-mail and PDF versions for Drupal 6.x prior to 6.x-1.5

Drupal core is not affected. If you do not use the contributed Printer, e-mail and PDF versions module, there is nothing you need to do.

Solution

Install the latest version:

See also the Printer, e-mail and PDF versions project page.

Reported by

Stéphane Corlosquet

Fixed by

Peter Wolanin

Contact

The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.