* Advisory ID: DRUPAL-SA-CONTRIB-2011-029 * Project: Taxonomy Filter [1] (third-party module) * Version: 6.x, 7.x * Date: 2011-July-20 * Security risk: Moderately critical [2] * Exploitable from: Remote * Vulnerability: Cross Site Scripting
-------- DESCRIPTION ---------------------------------------------------------
The Taxonomy Filter module enables users to filter taxonomy listings to find content tagged by multiple terms.
Older versions of the module were susceptible to a Cross Site Scripting (XSS) attack by way of vocabulary names. The vulnerability was mitigated by the fact that an attacker must have a role with the "administer taxonomy" permission. The 6.x-1.6 release of Taxonomy Filter also corrects an XSS issue in Taxonomy Filter menu names that requires the "administer site configuration" permission. Vulnerabilities that require the "administer site configuration" permission to exploit [3] do not necessitate Security Advisories, however no Advisory had been issued for previous insecure releases.
-------- VERSIONS AFFECTED ---------------------------------------------------
* 6.x-1.3 and earlier * 7.x-1.x-dev
Drupal core is not affected. If you do not use the contributed Taxonomy Filter [4] module, there is nothing you need to do.
-------- SOLUTION ------------------------------------------------------------
Install the latest version:
* If you use the Taxonomy Filter module for Drupal 6.x upgrade to 6.x-1.6 [5] * If you use the Taxonomy Filter module for Drupal 7.x upgrade to the latest 7.x-1.x-dev [6] release
See also the Taxonomy Filter [7] project page.
-------- REPORTED BY ---------------------------------------------------------
* Sam Oldak
-------- FIXED BY ------------------------------------------------------------
* Jim Berry [8] the module maintainer
-------- CONTACT AND MORE INFORMATION ----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact [9].
Learn more about the Drupal Security team and their policies [10], writing secure code for Drupal [11], and securing your site [12].
[1] http://drupal.org/project/taxonomy_filter [2] http://drupal.org/security-team/risk-levels [3] http://drupal.org/security-advisory-policy [4] http://drupal.org/project/taxonomy_filter [5] http://drupal.org/node/1223666 [6] http://drupal.org/node/96252 [7] http://drupal.org/project/taxonomy_filter [8] http://drupal.org/user/240748 [9] http://drupal.org/contact [10] http://drupal.org/security-team [11] http://drupal.org/writing-secure-code [12] http://drupal.org/security/secure-configuration