CVE-2014-8746: XSS
Published Oct 13, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2 through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.
Affected Software
2 affected components
Drupal Skeleton theme=7.x-1.2
Drupal Skeleton theme=7.x-1.3
Remediation
Patch Available
Event History
Oct 13, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8746?
CVE-2014-8746 is classified as a high-severity cross-site scripting vulnerability.
2
How do I fix CVE-2014-8746?
To fix CVE-2014-8746, update the Skeleton theme to version 7.x-1.4 or later.
3
Who is affected by CVE-2014-8746?
CVE-2014-8746 affects users of the Skeleton theme versions 7.x-1.2 and 7.x-1.3 in Drupal.
4
What are the implications of CVE-2014-8746?
The implications of CVE-2014-8746 include the potential for remote authenticated users to inject malicious scripts.
5
What should I do if I cannot upgrade from the affected versions of CVE-2014-8746?
If you cannot upgrade, consider applying custom security measures, such as restricting user permissions.