[Security-news] SA-CONTRIB-2010-076 - Dashboard - Cross Site Scripting (CSS)

security-news at drupal.org security-news at drupal.org
Wed Jul 28 18:24:32 UTC 2010


  * Advisory ID: SA-CONTRIB-2010-076
  * Project: Dashboard (third-party module)
  * Version: 6.x
  * Date: 2010-July-28
  * Security risk: Moderately critical
  * Exploitable from: Remote
  * Vulnerability: Cross Site Scripting

-------- DESCRIPTION:  
--------------------------------------------------------

The dashboard module allows users to create a personalized set of pages of
widgets created from existing blocks and nodes (like iGoogle). The module
does not escape user generated names for tags & titles associated with
default widgets that are added to a user dashboard page, leading to a Cross
Site Scripting (XSS [1]) vulnerability. Users with the permission to access
or create default dashboard widgets is vulnerable to attack. A malicious user
needs the permission "administer dashboard defaults" to exploit the
vulnerability.
-------- VERSIONS AFFECTED:  
--------------------------------------------------

  * Dashboard module for Drupal 6.x versions prior to 6.x-2.1 [2]

Drupal core is not affected. If you do not use the contributed Dashboard [3]
module, there is nothing you need to do.

-------- SOLUTION:  
-----------------------------------------------------------

Install the latest version:

  * Upgrade to Dashboard 6.x-2.1 [4]

See also the Dashboard project page [5].

-------- REPORTED BY:  
--------------------------------------------------------

  * Greg Knaddison (greggles) [6] a member of the Drupal Security Team

-------- FIXED BY:  
-----------------------------------------------------------

  * Chris Miller [7], module maintainer
  * Greg Knaddison (greggles) [8] a member of the Drupal Security Team

The Drupal security team [9] can be reached at security at drupal.org [10] or
via the form at http://drupal.org/contact [11].

[1] http://en.wikipedia.org/wiki/Cross-site_scripting
[2] http://drupal.org/node/866628
[3] http://drupal.org/project/dashboard
[4] http://drupal.org/node/866628
[5] http://drupal.org/project/dashboard
[6] http://drupal.org/user/36762
[7] http://drupal.org/user/274027
[8] http://drupal.org/user/36762
[9] http://drupal.org/security-team
[10] http://drupal.org
[11] http://drupal.org/contact



More information about the Security-news mailing list