• Advisory ID: DRUPAL-SA-CONTRIB-2010-105
  • Project: Outline Designer (third-party module)
  • Version: 6.x
  • Date: 2010-December-01
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross-site Request Forgery

Description

Outline Designer allows for easier creation and management of items in a Book.

The Outline Designer modules does not properly protect some of its paths against Cross Site Request Forgeries (CSRF), allowing an attacker to get a user with the permission to administer site configuration to change any book nodes.

Versions affected

  • Outline Designer for Drupal 6.x prior to Outline Designer 6.x-1.2

Drupal core is not affected. If you do not use the contributed module Outline Designer there is nothing you need to do.

Solution

Install the latest version:

See also the Outline Designer project page.

Reported by

  • Bryan Ollendyke (btopro), module maintainer

Fixed by

  • Bryan Ollendyke (btopro), module maintainer

Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the form at http://drupal.org/contact.
Learn more about the team and their policies, writing secure code for Drupal, and secure configuration of your site.