CVE-2010-1303: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy Filter module 6.x before 6.x-1.1 for Drupal allow remote authenticated users, with administer taxonomy permissions or create node permissions when free tagging is enabled, to inject arbitrary web script or HTML via vocabulary (1) names, (2) terms, and (3) filter menus.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1303?
CVE-2010-1303 has a moderate severity level due to its potential to allow unauthorized script injection via cross-site scripting vulnerabilities.
How do I fix CVE-2010-1303?
To fix CVE-2010-1303, upgrade the Taxonomy Filter module to version 6.x-1.1 or later.
Who is affected by CVE-2010-1303?
Remote authenticated users with administer taxonomy permissions or create node permissions are affected by CVE-2010-1303 when free tagging is enabled.
What version of the Taxonomy Filter module contains the vulnerability in CVE-2010-1303?
The vulnerability in CVE-2010-1303 is present in the Taxonomy Filter module versions 6.x-1.0 and 6.x-1.x-dev.
What type of vulnerability is CVE-2010-1303?
CVE-2010-1303 is classified as multiple cross-site scripting (XSS) vulnerabilities.