Description: A vulnerability has been reported in the
Ubercart module for Drupal, which can be exploited by malicious users
to conduct script insertion attacks.
Input passed when editing certain unspecified product features is not
properly sanitised before being stored. This can be exploited to insert
arbitrary HTML and script code, which is executed in e.g. an
administrator"s browser session in context of an affected site when the
malicious data is viewed.
The vulnerability is reported in version 5.x prior to 5.x-1.0-rc3.
Solution: Update to version 5.x-1.0-rc3.
Provided and/or discovered by: Drupal security team
Original Advisory: http://drupal.org/node/250343
|