First published: Thu Sep 20 2012(Updated: )
Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Marvil07 Vote Up Down | =6.x-2.0 | |
Marvil07 Vote Up Down | =6.x-2.0-beta1 | |
Marvil07 Vote Up Down | =6.x-2.0-beta2 | |
Marvil07 Vote Up Down | =6.x-2.0-rc1 | |
Marvil07 Vote Up Down | =6.x-2.1 | |
Marvil07 Vote Up Down | =6.x-2.2 | |
Marvil07 Vote Up Down | =6.x-2.3 | |
Marvil07 Vote Up Down | =6.x-2.4 | |
Marvil07 Vote Up Down | =6.x-2.5 | |
Marvil07 Vote Up Down | =6.x-2.6 | |
Marvil07 Vote Up Down | =6.x-2.7 | |
Marvil07 Vote Up Down | =6.x-2.x-dev | |
Drupal Drupal | ||
Marvil07 Vote Up Down | =6.x-3.0 | |
Marvil07 Vote Up Down | =6.x-3.0-alpha1 | |
Marvil07 Vote Up Down | =6.x-3.0-beta1 | |
Marvil07 Vote Up Down | =6.x-3.x-dev |
http://drupalcode.org/project/vote_up_down.git/commit/fe83aa4b8fa44d83a01494870a80d4651434f4c0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1627 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2012-1627, upgrade the Vote Up/Down module to version 6.x-2.8 or 6.x-3.1 or later.
CVE-2012-1627 affects users running the Vote Up/Down module versions 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 in Drupal.
If exploited, CVE-2012-1627 allows remote authenticated users to inject arbitrary web scripts or HTML into the application.
Yes, patches for CVE-2012-1627 are included in the newer versions of the Vote Up/Down module.