CVE-2013-1779: XSS
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Fresh theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1779?
CVE-2013-1779 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-1779?
To fix CVE-2013-1779, you should upgrade to Fresh theme version 7.x-1.4 or later.
Who is affected by CVE-2013-1779?
CVE-2013-1779 affects remote authenticated users with the administer themes permission in the Fresh theme before version 7.x-1.4.
What can an attacker do with CVE-2013-1779?
An attacker can inject arbitrary web scripts or HTML into the Fresh theme due to the XSS vulnerability in CVE-2013-1779.
Is there a known exploit for CVE-2013-1779?
Yes, CVE-2013-1779 has been documented and can be exploited by malicious users with the appropriate permissions.