• Advisory ID: DRUPAL-SA-2008-001
  • Project: Devel (third-party module)
  • Version: 5.x
  • Date: 2008-January-10
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

Description

The devel module contains many useful developer functions, such as a query log and the display of variables. The contents of the variable table is not escaped prior to display. Should an unprivileged user be able to control the contents of a site variable, it would be possible to inject arbitrary HTML and script code into these pages, which may lead to administrator access if certain conditions are met. Learn more about cross site scripting on Wikipedia.

Versions affected

  • Devel for Drupal 5.x before Devel 5.x-0.1

Drupal core is not affected. If you do not use the contributed Devel module, there is nothing you need to do.

Solution

Install the latest version:

See also the Devel project page.

Reported by

Frederic G. MARAND (FGM).

Contact

The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.