First published: Mon Dec 03 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the OM Maximenu module 6.x-1.x before 6.x-1.44 and 7.x-1.x before 7.x-1.44 for Drupal allow remote authenticated users with the "administer OM Maximenu" permission to inject arbitrary web script or HTML via the (1) Menu Title (2) Link Title, (3) Path Query, (4) Anchor, or (5) vocabulary names.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Daniel Honrade Om Maximenu | =6.x-1.0 | |
Daniel Honrade Om Maximenu | =6.x-1.0-rc1 | |
Daniel Honrade Om Maximenu | =6.x-1.0-rc2 | |
Daniel Honrade Om Maximenu | =6.x-1.0-rc3 | |
Daniel Honrade Om Maximenu | =6.x-1.0-rc4 | |
Daniel Honrade Om Maximenu | =6.x-1.0-rc5 | |
Daniel Honrade Om Maximenu | =6.x-1.0-rc6 | |
Daniel Honrade Om Maximenu | =6.x-1.0-rc7 | |
Daniel Honrade Om Maximenu | =6.x-1.1 | |
Daniel Honrade Om Maximenu | =6.x-1.2 | |
Daniel Honrade Om Maximenu | =6.x-1.3 | |
Daniel Honrade Om Maximenu | =6.x-1.4 | |
Daniel Honrade Om Maximenu | =6.x-1.5 | |
Daniel Honrade Om Maximenu | =6.x-1.6 | |
Daniel Honrade Om Maximenu | =6.x-1.7 | |
Daniel Honrade Om Maximenu | =6.x-1.8 | |
Daniel Honrade Om Maximenu | =6.x-1.9 | |
Daniel Honrade Om Maximenu | =6.x-1.10 | |
Daniel Honrade Om Maximenu | =6.x-1.11 | |
Daniel Honrade Om Maximenu | =6.x-1.12 | |
Daniel Honrade Om Maximenu | =6.x-1.13 | |
Daniel Honrade Om Maximenu | =6.x-1.14 | |
Daniel Honrade Om Maximenu | =6.x-1.15 | |
Daniel Honrade Om Maximenu | =6.x-1.16 | |
Daniel Honrade Om Maximenu | =6.x-1.17 | |
Daniel Honrade Om Maximenu | =6.x-1.18 | |
Daniel Honrade Om Maximenu | =6.x-1.19 | |
Daniel Honrade Om Maximenu | =6.x-1.20 | |
Daniel Honrade Om Maximenu | =6.x-1.21 | |
Daniel Honrade Om Maximenu | =6.x-1.22 | |
Daniel Honrade Om Maximenu | =6.x-1.23 | |
Daniel Honrade Om Maximenu | =6.x-1.24 | |
Daniel Honrade Om Maximenu | =6.x-1.25 | |
Daniel Honrade Om Maximenu | =6.x-1.26 | |
Daniel Honrade Om Maximenu | =6.x-1.27 | |
Daniel Honrade Om Maximenu | =6.x-1.28 | |
Daniel Honrade Om Maximenu | =6.x-1.29 | |
Daniel Honrade Om Maximenu | =6.x-1.30 | |
Daniel Honrade Om Maximenu | =6.x-1.31 | |
Daniel Honrade Om Maximenu | =6.x-1.32 | |
Daniel Honrade Om Maximenu | =6.x-1.33 | |
Daniel Honrade Om Maximenu | =6.x-1.34 | |
Daniel Honrade Om Maximenu | =6.x-1.35 | |
Daniel Honrade Om Maximenu | =6.x-1.36 | |
Daniel Honrade Om Maximenu | =6.x-1.37 | |
Daniel Honrade Om Maximenu | =6.x-1.38 | |
Daniel Honrade Om Maximenu | =6.x-1.39 | |
Daniel Honrade Om Maximenu | =6.x-1.40 | |
Daniel Honrade Om Maximenu | =6.x-1.41 | |
Daniel Honrade Om Maximenu | =6.x-1.42 | |
Daniel Honrade Om Maximenu | =6.x-1.43 | |
Daniel Honrade Om Maximenu | =6.x-1.x-dev | |
Daniel Honrade Om Maximenu | =7.x-1.0 | |
Daniel Honrade Om Maximenu | =7.x-1.1 | |
Daniel Honrade Om Maximenu | =7.x-1.2 | |
Daniel Honrade Om Maximenu | =7.x-1.3 | |
Daniel Honrade Om Maximenu | =7.x-1.4 | |
Daniel Honrade Om Maximenu | =7.x-1.5 | |
Daniel Honrade Om Maximenu | =7.x-1.6 | |
Daniel Honrade Om Maximenu | =7.x-1.7 | |
Daniel Honrade Om Maximenu | =7.x-1.8 | |
Daniel Honrade Om Maximenu | =7.x-1.9 | |
Daniel Honrade Om Maximenu | =7.x-1.10 | |
Daniel Honrade Om Maximenu | =7.x-1.11 | |
Daniel Honrade Om Maximenu | =7.x-1.12 | |
Daniel Honrade Om Maximenu | =7.x-1.13 | |
Daniel Honrade Om Maximenu | =7.x-1.14 | |
Daniel Honrade Om Maximenu | =7.x-1.15 | |
Daniel Honrade Om Maximenu | =7.x-1.16 | |
Daniel Honrade Om Maximenu | =7.x-1.17 | |
Daniel Honrade Om Maximenu | =7.x-1.18 | |
Daniel Honrade Om Maximenu | =7.x-1.19 | |
Daniel Honrade Om Maximenu | =7.x-1.20 | |
Daniel Honrade Om Maximenu | =7.x-1.21 | |
Daniel Honrade Om Maximenu | =7.x-1.22 | |
Daniel Honrade Om Maximenu | =7.x-1.23 | |
Daniel Honrade Om Maximenu | =7.x-1.24 | |
Daniel Honrade Om Maximenu | =7.x-1.25 | |
Daniel Honrade Om Maximenu | =7.x-1.26 | |
Daniel Honrade Om Maximenu | =7.x-1.27 | |
Daniel Honrade Om Maximenu | =7.x-1.28 | |
Daniel Honrade Om Maximenu | =7.x-1.29 | |
Daniel Honrade Om Maximenu | =7.x-1.30 | |
Daniel Honrade Om Maximenu | =7.x-1.31 | |
Daniel Honrade Om Maximenu | =7.x-1.32 | |
Daniel Honrade Om Maximenu | =7.x-1.33 | |
Daniel Honrade Om Maximenu | =7.x-1.34 | |
Daniel Honrade Om Maximenu | =7.x-1.35 | |
Daniel Honrade Om Maximenu | =7.x-1.36 | |
Daniel Honrade Om Maximenu | =7.x-1.37 | |
Daniel Honrade Om Maximenu | =7.x-1.38 | |
Daniel Honrade Om Maximenu | =7.x-1.39 | |
Daniel Honrade Om Maximenu | =7.x-1.40 | |
Daniel Honrade Om Maximenu | =7.x-1.41 | |
Daniel Honrade Om Maximenu | =7.x-1.42 | |
Daniel Honrade Om Maximenu | =7.x-1.43 | |
Daniel Honrade Om Maximenu | =7.x-1.x-dev | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-5553 is classified as moderately critical due to potential cross-site scripting (XSS) vulnerabilities.
To fix CVE-2012-5553, update the OM Maximenu module to the latest version, specifically to 6.x-1.44 or 7.x-1.44 or later.
CVE-2012-5553 affects users with the 'administer OM Maximenu' permission on versions of the OM Maximenu module prior to 6.x-1.44 and 7.x-1.44.
CVE-2012-5553 allows remote authenticated users to inject arbitrary web scripts or HTML through affected fields, leading to XSS attacks.
Versions of OM Maximenu from 6.x-1.0 to 6.x-1.43 and 7.x-1.0 to 7.x-1.43 are vulnerable to CVE-2012-5553.