[Security-news] SA-CONTRIB-2009-028 - Feed Block - Cross Site Scripting

security-news at drupal.org security-news at drupal.org
Wed May 13 16:59:32 UTC 2009


  * Advisory ID: DRUPAL-SA-CONTRIB-2009-028
  * Project: Feed Block (third-party module)
  * Version: 6.x
  * Date: 2009-May-13
  * Security risk: Less critical
  * Exploitable from: Remote
  * Vulnerability: Cross Site Scripting

-------- DESCRIPTION  
---------------------------------------------------------

The Feed Block module creates a block with one external(syndicated) article
for each feed source from selected feed category. Feed block doesn't properly
escapes aggregator items allowing users with administer news feeds permission
to inject arbitrary code into the site. Such a cross site scripting (XSS)
attack may lead to a malicious user gaining full administrative access.
-------- VERSIONS AFFECTED  
---------------------------------------------------

  * Feed Block 6.x-1.x prior to 6.x-1.1

Drupal core is not affected. If you do not use the contributed Feed Block
module, there is nothing you need to do.
-------- SOLUTION  
------------------------------------------------------------

Upgrade to the latest version:
  * If you use Feed Block 6.x-1.x upgrade to Feed Block 6.x-1.1 [1]

See also the Feed Block project page [2].
-------- REPORTED BY  
---------------------------------------------------------

Jakub Suchy [3] of the Drupal Security Team [4].
-------- FIXED BY  
------------------------------------------------------------

Ivan Jaros [5].
-------- CONTACT  
-------------------------------------------------------------

The security contact for Drupal can be reached at security at drupal.org or
via the form at http://drupal.org/contact.

[1] http://drupal.org/node/453098
[2] http://drupal.org/project/feed_block
[3] http://drupal.org/user/31977
[4] http://drupal.org/security-team
[5] http://drupal.org/user/135190



More information about the Security-news mailing list