CVE-2015-4373: XSS
Published Jun 15, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the OG tabs module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes posted in an Organic Groups group.
Affected Software
1 affected component
Og Tabs Project Og Tabs Drupal<=7.x-1.0
Remediation
Patch Available
Patch Available
Event History
Jun 15, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4373?
CVE-2015-4373 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-4373?
To fix CVE-2015-4373, upgrade the OG tabs module to version 7.x-1.1 or later.
3
What type of vulnerability is CVE-2015-4373?
CVE-2015-4373 is classified as a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2015-4373?
CVE-2015-4373 affects remote authenticated users with specific permissions in the OG tabs module for Drupal.
5
What is the impact of exploiting CVE-2015-4373?
Exploiting CVE-2015-4373 allows attackers to inject arbitrary web scripts or HTML into web pages viewed by other users.