First published: Wed Sep 19 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the Submenu Tree module before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thinkleft Submenu Tree | <=6.x-1.4 | |
Thinkleft Submenu Tree | =5.x-0.1 | |
Thinkleft Submenu Tree | =5.x-0.2 | |
Thinkleft Submenu Tree | =5.x-0.3 | |
Thinkleft Submenu Tree | =5.x-0.4 | |
Thinkleft Submenu Tree | =5.x-1.0 | |
Thinkleft Submenu Tree | =6.x-1.0 | |
Thinkleft Submenu Tree | =6.x-1.1 | |
Thinkleft Submenu Tree | =6.x-1.2 | |
Thinkleft Submenu Tree | =6.x-1.3 | |
Thinkleft Submenu Tree | =6.x-1.x-dev | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1651 is classified as a cross-site scripting (XSS) vulnerability that can allow remote authenticated users to inject malicious scripts.
To mitigate CVE-2012-1651, upgrade the Submenu Tree module to version 6.x-1.5 or later.
CVE-2012-1651 affects Submenu Tree module versions prior to 6.x-1.5, including 5.x-0.1 through 5.x-0.4 and 6.x-1.0 through 6.x-1.3.
If exploited, CVE-2012-1651 can lead to unauthorized script execution in the context of a user's session, potentially compromising sensitive data.
You can determine vulnerability by checking the installed version of the Submenu Tree module against the affected versions listed in CVE-2012-1651.