First published: Wed Mar 27 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Simple Corporate theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Devsaran Corporate | <=7.x-1.3 | |
Devsaran Corporate | =7.x-1.0 | |
Devsaran Corporate | =7.x-1.1 | |
Devsaran Corporate | =7.x-1.2 | |
Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1787 has a moderate severity level, allowing potential XSS attacks on affected systems.
To fix CVE-2013-1787, upgrade to Simple Corporate theme version 7.x-1.4 or higher.
CVE-2013-1787 affects remote authenticated users with administer themes permission on versions of the Simple Corporate theme before 7.x-1.4.
CVE-2013-1787 allows attackers to inject arbitrary web scripts or HTML into the Simple Corporate theme.
If CVE-2013-1787 is not addressed, it poses a risk of successful cross-site scripting attacks leading to data compromise.