• Advisory ID: DRUPAL-SA-CONTRIB-2009-028
  • Project: Feed Block (third-party module)
  • Version: 6.x
  • Date: 2009-May-13
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Feed Block module creates a block with one external(syndicated) article for each feed source from selected feed category. Feed block doesn't properly escapes aggregator items allowing users with administer news feeds permission to inject arbitrary code into the site. Such a cross site scripting (XSS) attack may lead to a malicious user gaining full administrative access.

Versions affected

  • Feed Block 6.x-1.x prior to 6.x-1.1

Drupal core is not affected. If you do not use the contributed Feed Block module, there is nothing you need to do.

Solution

Upgrade to the latest version:

See also the Feed Block project page.

Reported by

Jakub Suchy of the Drupal Security Team.

Fixed by

Ivan Jaros.

Contact

The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.