PT-2012-4196 · Drupal · Smart Breadcrumb

Publicado

2012-06-27

·

Atualizado

2017-08-29

·

CVE-2012-2705

CVSS v2.0

2.1

Baixa

VetorAV:N/AC:H/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Smart Breadcrumb module versions 6.x-1.x before 6.x-1.3
Description The issue concerns the filter titles function, which does not properly convert a title to plain-text. This allows remote authenticated users with create or edit node permissions to conduct cross-site scripting (XSS) attacks via the title parameter.
Recommendations For Smart Breadcrumb module versions 6.x-1.x before 6.x-1.3, update to version 6.x-1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the filter titles function or limiting the ability to create or edit nodes to trusted users until the update can be applied.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-2705

Produtos afetados

Smart Breadcrumb