CVE-2014-8076: XSS
Cross-site scripting (XSS) vulnerability in the Professional theme 7.x before 7.x-2.04 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to custom copyright information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8076?
CVE-2014-8076 has a medium severity rating as it allows remote authenticated users to exploit cross-site scripting vulnerabilities.
How do I fix CVE-2014-8076?
To fix CVE-2014-8076, update the Professional theme to version 7.x-2.04 or later.
Who can exploit CVE-2014-8076?
CVE-2014-8076 can be exploited by remote authenticated users who have the 'administer themes' permission.
Which versions of the Professional theme are affected by CVE-2014-8076?
CVE-2014-8076 affects the Professional theme versions 7.x-1.0 to 7.x-2.03.
What type of vulnerability is CVE-2014-8076?
CVE-2014-8076 is a cross-site scripting (XSS) vulnerability that allows arbitrary web script or HTML injection.