CVE-2007-3817: XSS
Cross-site scripting (XSS) vulnerability in the LoginToboggan module 4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal, when configured to display a "Log out" link, allows remote attackers to inject arbitrary web script or HTML via a crafted username. NOTE: Drupal sanitizes the username by removing certain characters, so this might not be a vulnerability on default installations.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3817?
CVE-2007-3817 is considered to have a high severity due to its ability to allow remote attackers to inject arbitrary web scripts or HTML.
How do I fix CVE-2007-3817?
To fix CVE-2007-3817, you should upgrade the LoginToboggan module to a version released on or after July 12, 2007.
Which versions are vulnerable to CVE-2007-3817?
Versions 4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev of the LoginToboggan module prior to July 12, 2007 are vulnerable to CVE-2007-3817.
What type of attack does CVE-2007-3817 facilitate?
CVE-2007-3817 facilitates Cross-Site Scripting (XSS) attacks, allowing attackers to execute scripts in the context of another user.
Can CVE-2007-3817 be exploited without user interaction?
Yes, CVE-2007-3817 can be exploited remotely without requiring user interaction, making it particularly dangerous.