First published: Wed Sep 19 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the Taxonomy Views Integrator (TVI) module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, related to "views pages."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Collectivecolors Taxonomy View Integrator Module | =6.x-1.0 | |
Collectivecolors Taxonomy View Integrator Module | =6.x-1.0-beta1 | |
Collectivecolors Taxonomy View Integrator Module | =6.x-1.0-beta2 | |
Collectivecolors Taxonomy View Integrator Module | =6.x-1.0-beta3 | |
Collectivecolors Taxonomy View Integrator Module | =6.x-1.0-beta4 | |
Collectivecolors Taxonomy View Integrator Module | =6.x-1.1 | |
Collectivecolors Taxonomy View Integrator Module | =6.x-1.2 | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1653 has a medium severity rating as it allows for cross-site scripting (XSS) which can potentially harm users.
To fix CVE-2012-1653, upgrade the Taxonomy Views Integrator module to version 6.x-1.3 or later.
CVE-2012-1653 affects users of the Taxonomy Views Integrator module versions 6.x-1.0 through 6.x-1.2 in Drupal.
Using CVE-2012-1653, attackers can execute arbitrary web scripts or HTML in a user's browser during a session.
CVE-2012-1653 can be exploited by remote authenticated users, indicating a moderate level of exploitability.