PT-2015-7753 · Drupal · Mayo Theme

Publicado

2015-11-17

·

Atualizado

2015-11-18

·

CVE-2015-8233

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MAYO theme versions 7.x-1.x before 7.x-1.4 MAYO theme versions 7.x-2.x before 7.x-2.6
Description A cross-site scripting (XSS) issue exists, allowing remote administrators with the "Administer themes" permission to inject arbitrary web script or HTML via unspecified vectors related to theme settings.
Recommendations For MAYO theme versions 7.x-1.x before 7.x-1.4, update to version 7.x-1.4 or later. For MAYO theme versions 7.x-2.x before 7.x-2.6, update to version 7.x-2.6 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8233

Produtos afetados

Mayo Theme