CVE-2010-1984: XSS
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 5.x before 5.x-1.5 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the taxonomy term name in a Breadcrumb display.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1984?
CVE-2010-1984 is considered a medium severity vulnerability that allows for cross-site scripting attacks.
How do I fix CVE-2010-1984?
To fix CVE-2010-1984, you should update the Taxonomy Breadcrumb module to version 5.x-1.5 or 6.x-1.1 or later.
Who is affected by CVE-2010-1984?
CVE-2010-1984 affects users of the Taxonomy Breadcrumb module versions 5.x-1.0 to 5.x-1.4 and 6.x-0.1-beta to 6.x-1.0.
What are the potential impacts of CVE-2010-1984?
The potential impacts of CVE-2010-1984 include unauthorized script execution on the affected Drupal site.
Can unauthenticated users exploit CVE-2010-1984?
No, only remote authenticated users with administer taxonomy permissions can exploit CVE-2010-1984.