CVE-2014-8077: XSS
Cross-site scripting (XSS) vulnerability in the NewsFlash theme 6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to font family CSS property.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8077?
CVE-2014-8077 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-8077?
To fix CVE-2014-8077, upgrade the NewsFlash theme to version 6.x-1.7 or 7.x-2.5 or later.
Who is affected by CVE-2014-8077?
CVE-2014-8077 affects remote authenticated users with 'administer themes' permission on vulnerable versions of the NewsFlash theme.
What type of vulnerability is CVE-2014-8077?
CVE-2014-8077 is a Cross-Site Scripting (XSS) vulnerability.
What could an attacker do with CVE-2014-8077?
An attacker could inject arbitrary web script or HTML into a vulnerable installation, potentially compromising the security of the application.