* Advisory ID: DRUPAL-SA-CONTRIB-2012-024 * Project: MediaFront [1] (third-party module) * Version: 6.x, 7.x * Date: 2012-February-29 * Security risk: Less Critical [2] * Exploitable from: Remote * Vulnerability: Cross Site Scripting -------- DESCRIPTION --------------------------------------------------------- Within the MediaFront module, there is a PHP library for handling the stand alone application of the Open Standard Media player. Within this library, both the $_SESSION and $_SERVER variables are handled without proper checks to make sure that no malicious code is injected within these variables. -------- VERSIONS AFFECTED --------------------------------------------------- * MediaFront 6.x-1.x versions prior to 6.x-1.5. * MediaFront 7.x-1.x versions prior to 7.x-1.5. Drupal core is not affected. If you do not use the contributed MediaFront [3] module, there is nothing you need to do. -------- SOLUTION ------------------------------------------------------------ Install the latest version: * If you use the Mediafront module for Drupal 6.x, upgrade to Mediafront 6.x-1.5 [4] * If you use the Mediafront module for Drupal 7.x, upgrade to Mediafront 7.x-1.5 [5] See also the MediaFront [6] project page. -------- REPORTED BY --------------------------------------------------------- * Óscar Estepa [7] -------- FIXED BY ------------------------------------------------------------ * Travis Tidwell [8] the module maintainer -------- COORDINATED BY ------------------------------------------------------ * Michael Hess [9] of the Drupal Security Team -------- CONTACT AND MORE INFORMATION ---------------------------------------- The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact [10]. Learn more about the Drupal Security team and their policies [11], writing secure code for Drupal [12], and securing your site [13]. [1] http://drupal.org/project/mediafront [2] http://drupal.org/security-team/risk-levels [3] http://drupal.org/project/mediafront [4] https://drupal.org/node/1460892 [5] https://drupal.org/node/1460894 [6] http://drupal.org/project/mediafront [7] http://drupal.org/user/1306904 [8] http://drupal.org/user/98581 [9] http://drupal.org/user/102818 [10] http://drupal.org/contact [11] http://drupal.org/security-team [12] http://drupal.org/writing-secure-code [13] http://drupal.org/security/secure-configuration _______________________________________________ Security-news mailing list Security-news@drupal.org http://lists.drupal.org/mailman/listinfo/security-news