Cross-site scripting (XSS) vulnerability in the path-based meta tag editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows remote authenticated users with the "Edit path based meta tags" permission to inject arbitrary web script or HTML via vectors related to deleting a Path-based Metatag.
References
Link | Resource |
---|---|
https://www.drupal.org/node/2295975 | Patch Vendor Advisory |
https://www.drupal.org/node/2296511 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2014-12-10 20:59
Updated : 2024-02-04 18:35
NVD link : CVE-2014-9362
Mitre link : CVE-2014-9362
CVE.ORG link : CVE-2014-9362
JSON object : View
Products Affected
meta_tags_quick_project
- meta_tags_quick
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')