Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Evans

#51006of 53,624
4.3Total CVSS
Vulnerabilities · 1
PT-2017-7308
4.3
2017-10-02
Drupal · Compass Rose · CVE-2015-7980
**Name of the Vulnerable Software and Affected Versions** Compass Rose module versions 6.x-1.x before 6.x-1.1 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via unspecified vectors. This is related to embedding a JavaScript library from an external source that was not reliable. **Recommendations** For Compass Rose module versions 6.x-1.x before 6.x-1.1, update to version 6.x-1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Compass Rose module until a patch is applied.