English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Drupal Gigya - Social optimization Module Cross-Site-Scripting Vulnerability


Secunia ID

SA48832

CVE-ID

CVE-2012-2117

Release Date

19 Apr 2012

Criticality

Less Critical

Solution Status

Vendor Patch

Software

Drupal Gigya - Social optimization Module 6.x

Where

From remote

Impact
Cross-Site Scripting

Cross-Site Scripting vulnerabilities allow a third party to manipulate the content or behaviour of a web application in a user's browser, without compromising the underlying system.

Different Cross-Site Scripting related vulnerabilities are also classified under this category, including "script insertion" and "cross-site request forgery".

Cross-Site Scripting vulnerabilities are often used against specific users of a website to steal their credentials or to conduct spoofing attacks.

Description

A vulnerability has been reported in the Gigya - Social optimization module for Drupal, which can be exploited by malicious people to conduct cross-site scripting attacks.

Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The vulnerability is reported in versions prior to 6.x-3.2.

Solution

Update to version 6.x-3.2.

Reported by

The vendor credits Marek Lyczba.

Original Advisory

SA-CONTRIB-2012-061:
http://drupal.org/node/1538704