- Advisory ID: DRUPAL-SA-CONTRIB-2009-072
- Project: RealName (third-party module)
- Version: 6.x
- Date: 2009-October-14
- Security risk: Moderately Critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
Description
The RealName module allows the administrator to choose fields from the user profile that will be used to add a "real name" element (method) to a user object. In some specific cases, the module does not sanitize before outputting the realname, resulting in a cross-site scripting (XSS) vulnerability. Such an attack may lead to a malicious user gaining full administrative access.
Versions affected
- RealName 6.x-1.x prior to 6.x-1.3
Drupal core is not affected. If you do not use the contributed RealName module, there is nothing you need to do.
Solution
Install the latest version:
- If you use the RealName for Drupal 6.x-1.x upgrade to RealName 6.x-1.3
See also the RealName module project page.
Reported by
Fixed by
NancyDru, the module maintainer
Contact
The security team for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.