The CSP Log module enhances any module that adds the CSP header to a site, by providing a reporting endpoint, custom storage, and aggregated reports that can be used to trace issues or adapt the CSP headers.
The module did not sufficiently sanitize user-supplied values used in database queries, resulting in an SQL injection vulnerability.
This vulnerability is mitigated by the fact that an attacker needs access to an account with the Access CSP reports permission to exploit the SQL Injection.
Install the latest version:
- If you use the CSP Log module, upgrade to CSP Log 1.0.2.
- Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team