• Advisory ID: DRUPAL-SA-CONTRIB-2010-012
  • Project: ODF Import (third-party module)
  • Version: 6.x-1.0
  • Date: 2010-February-3
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

ODF Import module enables users of a Drupal site to import content created in the ODF format (e.g. using OpenOffice.org). When importing content it always used an input format which might not be available to the user importing the content leading to a cross-site scripting (XSS) vulnerability. Such an attack may lead to a malicious user gaining full administrative access. Mitigating factors: this only impacts sites which also use the ODF Import module, where users have the "import odf" permission.

Versions affected

  • ODF Import for Drupal 6.x prior to 6.x-1.0

Drupal core is not affected. If you do not use the contributed ODF Import module, there is nothing you need to do.

Solution

Upgrade to the latest version:

See also the ODF Import project page.

Reported by

Fixed by

Contact

The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.