-------- DESCRIPTION ---------------------------------------------------------
The Meta tags quick module provides a simple tool to add meta tags to a site. The module doesn't consistently filter user input which could lead to a Cross Site Scripting vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer content types", "administer vocabularies and terms" or another permission that allows modifying the names of entity bundles.
-------- VERSIONS AFFECTED ---------------------------------------------------
* Meta tags quick 7.x-2.x versions prior to 7.x-2.3.
Drupal core is not affected. If you do not use the contributed Meta tags quick [1] module, there is nothing you need to do.
-------- SOLUTION ------------------------------------------------------------
Install the latest version:
* If you use the Meta tags quick module for Drupal 7.x, upgrade to Meta tags quick 7.x-2.3 [2].
See also the Meta tags quick [3] project page.
-------- REPORTED BY ---------------------------------------------------------
* Michael Smith [4]
-------- FIXED BY ------------------------------------------------------------
* Michael Smith [5] * valthebald [6] the module maintainer
-------- COORDINATED BY ------------------------------------------------------
* Dave Reid [7] of the Drupal Security Team
-------- CONTACT AND MORE INFORMATION ----------------------------------------
The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact [8].
Learn more about the Drupal Security team and their policies [9], writing secure code for Drupal [10], and securing your site [11].
[1] http://drupal.org/project/metatags_quick [2] http://drupal.org/node/1370878 [3] http://drupal.org/project/metatags_quick [4] http://drupal.org/user/1291584 [5] http://drupal.org/user/1291584 [6] http://drupal.org/user/239562 [7] http://drupal.org/user/53892 [8] http://drupal.org/contact [9] http://drupal.org/security-team [10] http://drupal.org/writing-secure-code [11] http://drupal.org/security/secure-configuration