First published: Sat Oct 06 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Lingotek module 6.x-1.x before 6.x-1.40 for Drupal allow remote authenticated users to inject arbitrary web script or HTML when (1) creating or (2) editing page content.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lingotek Lingotek | <=6.x-1.4 | |
Lingotek Lingotek | =6.x-1.0 | |
Lingotek Lingotek | =6.x-1.1 | |
Lingotek Lingotek | =6.x-1.3 | |
Lingotek Lingotek | =6.x-1.31 | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1624 is classified as a medium severity vulnerability due to its potential for exploitation in cross-site scripting attacks.
To fix CVE-2012-1624, upgrade the Lingotek module to version 6.x-1.40 or later.
CVE-2012-1624 affects users of the Lingotek module versions prior to 6.x-1.40 in Drupal.
The consequences of CVE-2012-1624 include the potential for remote authenticated users to inject arbitrary web scripts or HTML.
There have been reports indicating that CVE-2012-1624 may be actively exploited in the wild, emphasizing the need for immediate patching.