First published: Wed Jun 25 2008(Updated: )
Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote authenticated users, with create post permissions, to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Trailscout Module | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2849 is classified as a critical cross-site scripting (XSS) vulnerability.
To fix CVE-2008-2849, update the TrailScout module to version 5.x-1.4 or later.
Remote authenticated users with create post permissions are affected by CVE-2008-2849.
CVE-2008-2849 allows attackers to inject arbitrary web scripts or HTML into the affected application.
All versions of the TrailScout module prior to 5.x-1.4 are vulnerable to CVE-2008-2849.