First published: Tue Jun 25 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the MP3 Player module for Drupal 6.x allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the file name of a MP3 file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jordan De Laune Mp3 Player | <=6.x-1.1 | |
Jordan De Laune Mp3 Player | =6.x-1.0 | |
Jordan De Laune Mp3 Player | =6.x-1.0-beta1 | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1971 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
To mitigate CVE-2013-1971, update the MP3 Player module for Drupal to version 6.x-1.1 or higher.
CVE-2013-1971 affects users of the MP3 Player module for Drupal versions 6.x-1.0, 6.x-1.0-beta1, and 6.x-1.1.
CVE-2013-1971 is a cross-site scripting (XSS) vulnerability.
No, CVE-2013-1971 requires authentication, as it affects remote authenticated users with specific permissions.