PT-2012-4196 · Drupal · Smart Breadcrumb
Publicado
2012-06-27
·
Atualizado
2017-08-29
·
CVE-2012-2705
CVSS v2.0
2.1
Baixa
| Vetor | AV:N/AC:H/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Smart Breadcrumb module versions 6.x-1.x before 6.x-1.3
Description
The issue concerns the
filter titles function, which does not properly convert a title to plain-text. This allows remote authenticated users with create or edit node permissions to conduct cross-site scripting (XSS) attacks via the title parameter.Recommendations
For Smart Breadcrumb module versions 6.x-1.x before 6.x-1.3, update to version 6.x-1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
filter titles function or limiting the ability to create or edit nodes to trusted users until the update can be applied.Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Smart Breadcrumb