PT-2007-5053 · Drupal · Logintoboggan

Published

2007-07-17

·

Updated

2012-10-31

·

CVE-2007-3818

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: LoginToboggan module versions 5.x-1.x-dev before 20070712
Description: The issue allows remote authenticated users with administer blocks permission to inject arbitrary JavaScript and gain privileges via the message displayed above the default user login block.
Recommendations: For LoginToboggan module versions 5.x-1.x-dev before 20070712, update to a version released after 20070712 to resolve the issue. As a temporary workaround, consider restricting access to the "administer blocks" permission to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3818

Affected Products

Logintoboggan