• Advisory ID: DRUPAL-SA-CONTRIB-2009-097
  • Project: Organic Groups Vocabulary (third-party module)
  • Version: 6.x
  • Date: 2009-November-4
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Organic Groups Vocabulary module enables a vocabulary to be restricted for use to a specific Organic Group. The module does not sanitize before outputting the group title in some cases, resulting in a cross-site scripting (XSS) vulnerability. Such an attack may lead to a malicious user gaining full administrative access.

Versions affected

Drupal core is not affected. If you do not use the contributed Organic Groups Vocabulary module, there is nothing you need to do.

Solution

Upgrade to the latest version:

  • If you use Organic Groups Vocabulary for Drupal 6.x upgrade to version 6.x-1.1

See also the Organic Groups Vocabulary module project page.

Reported by

Fixed by

Contact

The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.