CVE-2014-7979: XSS
Published Oct 8, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the SimpleCorp theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.
Affected Software
1 affected component
Drupal SimpleCorp=7.x-1.0
Remediation
Patch Available
Event History
Oct 8, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7979?
CVE-2014-7979 has a moderate severity rating due to its impact on web application security.
2
How do I fix CVE-2014-7979?
To fix CVE-2014-7979, upgrade to the SimpleCorp theme version 7.x-1.1 or later.
3
Who is affected by CVE-2014-7979?
CVE-2014-7979 affects remote authenticated users with the 'administer themes' permission in Drupal.
4
What type of vulnerability is CVE-2014-7979?
CVE-2014-7979 is classified as a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2014-7979?
Attackers exploiting CVE-2014-7979 can inject arbitrary web script or HTML into the affected Drupal theme.