CVE-2014-8743: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) Role or (2) Organic Group name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8743?
CVE-2014-8743 has a moderate severity rating due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2014-8743?
You can fix CVE-2014-8743 by updating the Maestro module to version 7.x-1.4 or later.
Who is affected by CVE-2014-8743?
CVE-2014-8743 affects remote authenticated users in Drupal using the Maestro module version 7.x-1.x before 7.x-1.4.
What types of attacks can CVE-2014-8743 facilitate?
CVE-2014-8743 can facilitate cross-site scripting (XSS) attacks by allowing the injection of arbitrary web scripts or HTML.
What versions of the Maestro module are vulnerable to CVE-2014-8743?
Versions 7.x-1.0 to 7.x-1.3 of the Maestro module are vulnerable to CVE-2014-8743.