Hotjar - Moderately Critical - Cross Site Scripting (XSS)

* Advisory ID: DRUPAL-SA-CONTRIB-2017-015
* Project: Hotjar (third-party module)
* Version: 7.x, 8.x
* Date: 2017-February-15
* Security risk: 12/25 ( Moderately Critical)
* Vulnerability: Cross Site Scripting

DESCRIPTION

This module enables you to add the Hotjar tracking system to your website.

The module doesn't sufficiently sanitize the Hotjar ID when including
tracking code.

This vulnerability is mitigated by the fact that an attacker must have a role
with the permission "administer hotjar".

VERSIONS AFFECTED

* Hotjar 7.x-1.x versions before 7.x-1.2
* Hotjar 8.x-1.x versions before 8.x-1.0

Drupal core is not affected. If you do not use the contributed Hotjar module, there is nothing you need to do.

SOLUTION

Install the latest version:

* If you use the Hotjar module for Drupal 7.x upgrade to Hotjar 7.x-1.2
* If you use the Hotjar module for Drupal 8.x upgrade to Hotjar 8.x-1.0

Also see the Hotjar project page.

Add new comment