Cross-site scripting (XSS) vulnerability in the OG tabs module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes posted in an Organic Groups group.
References
Configurations
History
21 Nov 2024, 02:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2015/04/25/6 - | |
References | () http://www.securityfocus.com/bid/73054 - | |
References | () https://www.drupal.org/node/2404115 - Patch | |
References | () https://www.drupal.org/node/2450427 - Patch, Vendor Advisory |
Information
Published : 2015-06-15 14:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-4373
Mitre link : CVE-2015-4373
CVE.ORG link : CVE-2015-4373
JSON object : View
Products Affected
og_tabs_project
- og_tabs
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')