First published: Wed Jul 25 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the Glossify Internal Links Auto SEO module for Drupal 6.x-2.5 and earlier allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wearepropeople Glossify Internal Links Auto Seo | <=6.x-2.5 | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2309 has a medium severity rating, allowing for potential cross-site scripting attacks.
To fix CVE-2012-2309, upgrade the Glossify Internal Links Auto SEO module to version 6.x-2.6 or later.
CVE-2012-2309 affects remote authenticated users with specific roles in Drupal 6.x installations running the vulnerable version of the module.
CVE-2012-2309 allows attackers to inject arbitrary web scripts or HTML, which can lead to session hijacking or data theft.
No, Drupal itself is not vulnerable; the vulnerability exists specifically in the Glossify Internal Links Auto SEO module.