PT-2012-3418 · Drupal · Data

Kurt Seifried

·

Published

2012-09-18

·

Updated

2012-12-20

·

CVE-2012-1654

CVSS v2.0

2.1

Low

VectorAV:N/AC:H/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Data module versions prior to 6.x-1.0 Data module versions prior to 7.x-1.0-alpha3
Description The issue allows remote authenticated users with the administer data tables permission to inject arbitrary web script or HTML. This is achieved via the title parameter in files such as data.views.inc and data ui/data ui.admin.inc.
Recommendations For Data module versions prior to 6.x-1.0, update to version 6.x-1.0 or later. For Data module versions prior to 7.x-1.0-alpha3, update to version 7.x-1.0-alpha3 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1654

Affected Products

Data