[Security-news] SA-CONTRIB-2010-061 - AddonChat - Multiple Vulnerabilities

security-news at drupal.org security-news at drupal.org
Wed May 26 20:16:09 UTC 2010


  * Advisory ID: DRUPAL-SA-CONTRIB-2010-061
  * Project: AddonChat (third-party module)
  * Version: 6.x-1.x
  * Date: 2010-May-26
  * Security risk: Highly Critical
  * Exploitable from: Remote
  * Vulnerability: Multiple (Privilege Escalation, Cross-site scripting)

-------- DESCRIPTION  
---------------------------------------------------------

The AddonChat module provides Drupal integration with the AddonChat Java chat
room.

Due to unsafe handling of the global $user object, failed authentication at
the custom addonchat_auth.php script will log in an attacker as the chosen
user.

Additionally, several configuration variables are not escaped correctly,
leading to a cross-site scripting vulnerability. Users with "access
administration pages" permission could add arbitrary HTML and javascript to
pages.

-------- VERSIONS AFFECTED  
---------------------------------------------------

  * AddonChat module for Drupal 6.x versions prior to 6.x-1.2

Drupal core is not affected. If you do not use the contributed AddonChat [1]
module, there is nothing you need to do.

-------- SOLUTION  
------------------------------------------------------------

Install the latest version.

  * If you use the AddonChat module for Drupal 6.x upgrade to AddonChat
    6.x-1.2 [2]

-------- REPORTED BY  
---------------------------------------------------------

  * Jonathan Hedstrom [3]
  * Dylan Tack [4] of the Drupal Security Team

-------- FIXED BY  
------------------------------------------------------------

  * Jonathan Hedstrom [5] and Chris Duerr [6], the module maintainer.

-------- CONTACT  
-------------------------------------------------------------

The security team for Drupal can be reached at security at drupal.org or via
the form at http://drupal.org/contact [7].

Read more about the Security Team and Security Advisories at
http://drupal.org/security.


[1] http://drupal.org/project/addonchat
[2] http://drupal.org/node/810260
[3] http://drupal.org/user/208732
[4] http://drupal.org/user/96647
[5] http://drupal.org/user/208732
[6] http://drupal.org/user/602324
[7] http://drupal.org/contact



More information about the Security-news mailing list