PT-2013-1825 · Drupal · Drupal Nodewords: D6 Meta Tags

Forest Monsen

·

Published

2013-01-03

·

Updated

2013-01-03

·

CVE-2012-5654

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Drupal Nodewords: D6 Meta Tags module versions prior to 6.x-1.14
Description The issue arises when the module is configured to automatically generate description meta tags from node text. It fails to properly filter node content, potentially allowing remote attackers to obtain sensitive information by reading the description, dc.description, or og:description meta tags.
Recommendations For versions prior to 6.x-1.14, update to version 6.x-1.14 or later to resolve the issue. As a temporary workaround, consider disabling the automatic generation of description meta tags from node text until the update is applied. Restrict access to sensitive node content to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5654

Affected Products

Drupal Nodewords: D6 Meta Tags