PT-2014-4256 · Drupal · Drupal Anonymous Posting Module

Published

2014-01-30

·

Updated

2017-08-29

·

CVE-2014-1611

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal Anonymous Posting module versions 7.x-1.2 through 7.x-1.3
Description A cross-site scripting issue exists, allowing remote attackers to inject arbitrary web script or HTML via the contact name field.
Recommendations For versions 7.x-1.2 and 7.x-1.3, consider disabling the Anonymous Posting module until a patch is available. Restrict access to the contact name field to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1611

Affected Products

Drupal Anonymous Posting Module