Release date:
Updated on:
Affected Systems:
Drupal 7.x
Drupal 6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57437
Drupal is an open-source content management platform.
Drupal 6.x, 7. some JS functions of x have the XSS reflection vulnerability in implementation. When DOM elements are selected, HTML code can be inserted into the webpage. The access bypass vulnerability exists in the Book and Image modules, attackers can exploit this vulnerability to bypass security restrictions.
<* Source: T. ashula
David Rothstein
Mark Lindsey
Kressin Roger
Christian Johansson
Anders Olsson
Saschadrupal
Link: http://drupal.org/SA-CORE-2013-001
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Drupal
------
Drupal has released a Security Bulletin (SA-CORE-2013-001) and patches for this:
SA-CORE-2013-001: SA-CORE-2013-001-Drupal core-Multiple vulnerabilities
Link: http://drupal.org/SA-CORE-2013-001