CVE-2013-1783: XSS
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in page--front.tpl.php in the Business theme before 7.x-1.8 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1783?
CVE-2013-1783 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2013-1783?
To fix CVE-2013-1783, upgrade the Business theme to version 7.x-1.8 or later.
Who is affected by CVE-2013-1783?
CVE-2013-1783 affects remote authenticated users with administer themes permission on the Business theme prior to version 7.x-1.8.
What type of vulnerability is CVE-2013-1783?
CVE-2013-1783 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
Is my version vulnerable to CVE-2013-1783?
If you are using the Business theme versions prior to 7.x-1.8, your version is vulnerable to CVE-2013-1783.