• Advisory ID: DRUPAL-SA-CONTRIB-2009-044
  • Project: Bubbletimer (third-party module)
  • Version: 6.x
  • Date: 2009-July-22
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

Description

Bubbletimer allows users to create timesheets based on nodes. It suffers from a cross-site scripting (XSS) vulnerability due to not properly sanitizing node titles before they are displayed. It is also vulnerable to cross-site request forgeries (CSRF) making it possible for users to unknowingly add nodes to, or remove nodes from, their timesheets. Together, these vulnerabilities could lead to an attacker gaining administrator access.

Additionally, the module does not respect node access restrictions when displaying node listings.

Versions affected

  • Bubbletimer for Drupal 6.x prior to Bubbletimer 6.x-1.5

Drupal core is not affected. If you do not use the contributed Bubbletimer module, there is nothing you need to do.

Solution

Upgrade to the latest version:

See also the Bubbletimer project page.

Reported by

Fixed by

Contact

The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.