CVE-2011-3373: XSS
Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3373?
CVE-2011-3373 is classified as a high severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
How do I fix CVE-2011-3373?
To fix CVE-2011-3373, upgrade the Drupal Views Bulk Operations module to a version later than 6.x-1.10.
Who is affected by CVE-2011-3373?
Users of the Drupal Views Bulk Operations module versions 6.x-1.0 through 6.x-1.10 are affected by CVE-2011-3373.
What type of vulnerability is CVE-2011-3373?
CVE-2011-3373 is a cross-site scripting (XSS) vulnerability that can be exploited via specially crafted URLs.
Can CVE-2011-3373 be exploited remotely?
Yes, CVE-2011-3373 can be exploited remotely by an attacker providing a malicious URL.