Cross-site scripting (XSS) vulnerability in the context administration sub-panel in the Site Banner module before 7.x-4.1 for Drupal allows remote authenticated users with the "Administer contexts" Context UI module permission to inject arbitrary web script or HTML via vectors related to context settings.
References
Configurations
History
21 Nov 2024, 02:18
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/60758 - | |
References | () http://www.securityfocus.com/bid/69343 - | |
References | () https://www.drupal.org/node/2324303 - Patch | |
References | () https://www.drupal.org/node/2324689 - Vendor Advisory |
Information
Published : 2014-10-21 15:55
Updated : 2025-04-12 10:46
NVD link : CVE-2014-8376
Mitre link : CVE-2014-8376
CVE.ORG link : CVE-2014-8376
JSON object : View
Products Affected
site_banner_project
- site_banner
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')