[Security-news] SA-CONTRIB-2010-049 - Wordpress Import - Access bypass

security-news at drupal.org security-news at drupal.org
Wed May 19 17:44:26 UTC 2010


  * Advisory ID: DRUPAL-SA-CONTRIB-2010-049
  * Project: Wordpress Import (third-party module)
  * Version: 6.x
  * Date: 2010-May-19
  * Security risk: Highly Critical
  * Exploitable from: Remote
  * Vulnerability: Access bypass

-------- DESCRIPTION  
---------------------------------------------------------

The Wordpress Import module provides the ability to import nodes from a
Wordpress WXR export file. The form to import a WXR file does not use the
correct access permission and allows any user to upload arbitrary files and
import data from a remote WRX file.
-------- VERSIONS AFFECTED  
---------------------------------------------------

  * Wordpress Import for Drupal 6.x versions prior to 6.x-2.1 including all
    versions of 6.x-1.x.

Drupal core is not affected. If you do not use the contributed Wordpress
Import [1] module, there is nothing you need to do.
-------- SOLUTION  
------------------------------------------------------------

Install the latest version and revoke the "import wordpress blog" permission
from untrusted roles.
  * If you use Wordpress Import 6.x-2.x or 6.x-1.x upgrade to Wordpress Import
    6.x-2.1 [2]. The Wordpress Import 6.x-1.x branch is no longer maintained.

*Important note*: Only give fully trusted users the "import wordpress blog"
permission. Wordpress Import 6.x-2.1 still allows a user with that permission
to upload arbitrary files.
-------- REPORTED BY  
---------------------------------------------------------

  * Jennifer Hodgdon [3].

-------- FIXED BY  
------------------------------------------------------------

  * Yann Rocq [4], module maintainer.
  * lavamind [5], module maintainer.

-------- CONTACT  
-------------------------------------------------------------

The security team for Drupal [6] can be reached at security at drupal.org or
via the form at http://drupal.org/contact.

[1] http://drupal.org/project/wordpress_import
[2] http://drupal.org/node/802810
[3] http://drupal.org/user/155601
[4] http://drupal.org/user/57294
[5] http://drupal.org/user/564674
[6] http://drupal.org/security-team



More information about the Security-news mailing list