- Advisory ID: DRUPAL-SA-CONTRIB-2010-013
- Project: Menu Breadcrumb (third-party module)
- Version: 6.x
- Date: 2010-February-03
- Security risk: Less critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
Description
The Menu Breadcrumb module allows to use the menu the current page belongs to as breadcrumb. The module does not properly sanitize parts of the provided block, leading to a cross-site scripting (XSS) vulnerability. Such an attack may lead to a malicious user gaining full administrative access. Mitigating factors: A user must have a role with the permission administer blocks to exploit this vulnerability.
Versions affected
- Menu Breadcrumb for Drupal 6.x prior to 6.x-1.3
Drupal core is not affected. If you do not use the contributed Menu Breadcrumb module, there is nothing you need to do.
Solution
Upgrade to the latest version:
- If you use Menu Breadcrumb for Drupal 6.x upgrade to Menu Breadcrumb 6.x-1.3
See also the Menu Breadcrumb project page.
Reported by
Fixed by
- Chris Burgess, the module maintainer
Contact
The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.