[Security-news] SA-CONTRIB-2011-029 - Taxonomy Filter - Cross Site Scripting

security-news at drupal.org security-news at drupal.org
Wed Jul 20 18:46:05 UTC 2011


  * Advisory ID: DRUPAL-SA-CONTRIB-2011-029
  * Project: Taxonomy Filter [1] (third-party module)
  * Version: 6.x, 7.x
  * Date: 2011-July-20
  * Security risk: Moderately critical [2]
  * Exploitable from: Remote
  * Vulnerability: Cross Site Scripting

-------- DESCRIPTION  
---------------------------------------------------------

The Taxonomy Filter module enables users to filter taxonomy listings to find
content tagged by multiple terms.

Older versions of the module were susceptible to a Cross Site Scripting (XSS)
attack by way of vocabulary names. The vulnerability was mitigated by the
fact that an attacker must have a role with the "administer taxonomy"
permission. The 6.x-1.6 release of Taxonomy Filter also corrects an XSS issue
in Taxonomy Filter menu names that requires the "administer site
configuration" permission. Vulnerabilities that require the "administer site
configuration" permission to exploit [3] do not necessitate Security
Advisories, however no Advisory had been issued for previous insecure
releases.

-------- VERSIONS AFFECTED  
---------------------------------------------------

  * 6.x-1.3 and earlier
  * 7.x-1.x-dev

Drupal core is not affected. If you do not use the contributed Taxonomy
Filter [4] module, there is nothing you need to do.

-------- SOLUTION  
------------------------------------------------------------

Install the latest version:

  * If you use the Taxonomy Filter module for Drupal 6.x upgrade to 6.x-1.6
    [5]
  * If you use the Taxonomy Filter module for Drupal 7.x upgrade to the latest
    7.x-1.x-dev [6] release

See also the Taxonomy Filter [7] project page.

-------- REPORTED BY  
---------------------------------------------------------

  * Sam Oldak

-------- FIXED BY  
------------------------------------------------------------

  * Jim Berry [8] the module maintainer

-------- CONTACT AND MORE INFORMATION  
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [9].

Learn more about the Drupal Security team and their policies [10], writing
secure code for Drupal [11], and securing your site [12].


[1] http://drupal.org/project/taxonomy_filter
[2] http://drupal.org/security-team/risk-levels
[3] http://drupal.org/security-advisory-policy
[4] http://drupal.org/project/taxonomy_filter
[5] http://drupal.org/node/1223666
[6] http://drupal.org/node/96252
[7] http://drupal.org/project/taxonomy_filter
[8] http://drupal.org/user/240748
[9] http://drupal.org/contact
[10] http://drupal.org/security-team
[11] http://drupal.org/writing-secure-code
[12] http://drupal.org/security/secure-configuration



More information about the Security-news mailing list