First published: Thu Nov 21 2019(Updated: )
Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Activity | =6.x-1.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2078 is considered a moderate severity vulnerability due to its impact on user data and possible exploitation for XSS attacks.
To fix CVE-2012-2078, update to the latest version of the Drupal Activity module that addresses this cross-site scripting vulnerability.
CVE-2012-2078 enables attackers to execute arbitrary JavaScript code in the context of the user's session, leading to potential data theft or session hijacking.
Any website using the Drupal Activity module version 6.x-1.x is vulnerable to CVE-2012-2078.
Cross-site scripting (XSS) in the context of CVE-2012-2078 allows an attacker to inject malicious scripts into web pages viewed by other users, compromising their security.