CVE-2010-1976: XSS
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb display.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1976?
CVE-2010-1976 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2010-1976?
To fix CVE-2010-1976, update the Taxonomy Breadcrumb module to version 6.x-1.1 or later.
Who is affected by CVE-2010-1976?
CVE-2010-1976 affects remote authenticated users with administer taxonomy permissions using vulnerable versions of the Taxonomy Breadcrumb module.
What impact does CVE-2010-1976 have?
CVE-2010-1976 allows attackers to inject arbitrary web scripts or HTML via the node title in a Breadcrumb display.
Which versions of the Taxonomy Breadcrumb module are vulnerable to CVE-2010-1976?
Versions 6.x-0.1-beta, 6.x-1.0, and 6.x-1.x-dev of the Taxonomy Breadcrumb module are vulnerable to CVE-2010-1976.