CVE-2015-5488: XSS
Cross-site scripting (XSS) vulnerability in the MailChimp Signup submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "administer mailchimp" permission to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5488?
CVE-2015-5488 has a moderate severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-5488?
To fix CVE-2015-5488, update the MailChimp module to version 7.x-3.3 or later.
Who is affected by CVE-2015-5488?
Remote authenticated users with the 'administer mailchimp' permission in Drupal versions prior to 7.x-3.3 are affected by CVE-2015-5488.
What type of vulnerability is CVE-2015-5488?
CVE-2015-5488 is classified as a cross-site scripting (XSS) vulnerability.
What can attackers do with CVE-2015-5488?
Attackers can potentially inject arbitrary web scripts or HTML, leading to further exploits if CVE-2015-5488 is exploited.